CVE-2026-4315: WatchGuard Fireware
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (DoS) condition in the Fireware Web UI by convincing an authenticated administrator into visiting a malicious web page.
Affected products
- WatchGuard Fireware: from 2025.1, before 2026.2 (fixed in 2026.2); from 12.5, before 12.5.18 (fixed in 12.5.18); from 11.8, before 11.12.4 (fixed in 11.12.4); version 11.12.4 only; from 12.0, before 12.12 (fixed in 12.12)
Published 2026-03-30. Last modified 2026-08-28.