Skip to content

WatchGuard Technologies Fireware OS: unsafe deserialization

High7.5CVE-2026-13046 · Published Sep 30, 2026 · updated Oct 1, 2026

A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's SAML single sign-on session handling (samld) allows an attacker who has already obtained the ability to write files on the appliance to execute arbitrary code in the context of the samld service by causing samld to load a maliciously crafted session file.

Affected versions

PackageAffectedFixed in
Fireware OS
Product
>= 2026.3, < 2026.3.22026.3.2
>= 2025.0, < 2026.2.32026.2.3
>= 12.0, < 12.12.312.12.3
>= 12.11, < 12.11.1012.11.10
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-502

More WatchGuard Technologies advisories

All WatchGuard Technologies
Advisory
WatchGuard Technologies Fireware OS: null pointer dereference
High8.7Sep 30
WatchGuard Technologies Fireware OS: integer overflow
High8.2Sep 30
WatchGuard Technologies Fireware OS: missing authorization
High7.1Sep 30
WatchGuard Technologies Fireware OS: missing authorization
High7.1Sep 30
WatchGuard Technologies Fireware OS: stack buffer overflow
High8.6Sep 30
WatchGuard Technologies Fireware OS: stack buffer overflow
High8.7Sep 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.