WatchGuard TechnologiesCVE-2026-13079
WatchGuard Technologies Mobile VPN with SSL Client: privilege escalation
High7.3CVE-2026-13079 · Published Jul 3, 2026 · updated Aug 10, 2026
A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the machine where the client is installed. This issue affects the Mobile VPN with SSL client for Windows up to and including 2026.2.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Mobile VPN with SSL Client Product | >= 12.0, < 2026.2.1 | 2026.2.1 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-732
More WatchGuard Technologies advisories
All WatchGuard Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 3 | WatchGuard Technologies Fireware OS: improper signature check | High8.6 | 2026.2.1+2 more |
| Jul 3 | WatchGuard Technologies Fireware OS: hard-coded credentials | Medium5.9 | 2026.2.1+2 more |
| Jul 3 | WatchGuard Technologies Fireware OS: out-of-bounds write | High7.7 | 2026.2.1+3 more |
| Jul 3 | WatchGuard Technologies Fireware OS: denial of service | Medium6.9 | 2026.2.1+3 more |
| Jul 3 | WatchGuard Technologies Fireware OS: cross-site scripting | Medium4.8 | 2026.2.1+3 more |
| Jul 3 | WatchGuard Technologies Fireware OS: cross-site scripting | Medium4.8 | 2026.2.1+3 more |