CVE-2026-86135: WatchGuard Dimension

High severity, CVSS 7.0. EPSS: 0.2% chance of exploitation in the next 30 days.

A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to trigger unauthorized snapshot creation by tricking an authenticated administrator into visiting a specially crafted web page.

Affected products

  • WatchGuard Dimension: from 2.0, before 2.3.1 (fixed in 2.3.1)

Published 2026-09-08. Last modified 2026-09-08.