CVE-2026-3987: WatchGuard Fireware
High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.
A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an elevated system process.
Affected products
- WatchGuard Fireware: from 2025.1, before 2026.2 (fixed in 2026.2); from 12.6.1, before 12.12 (fixed in 12.12)
Published 2026-04-01. Last modified 2026-08-14.