Skip to content

WatchGuard Technologies Fireware OS: stack buffer overflow

Critical9.3CVE-2026-13086 · Published Aug 28, 2026 · updated Sep 3, 2026

A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.

Affected versions

PackageAffectedFixed in
Fireware OS
Product
>= 2025.0, < 2026.2.22026.2.2
>= 12.0, < 12.12.212.12.2
>= 2026.3, < 2026.3.12026.3.1
>= 12.0, < 12.5.2012.5.20
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-121, CWE-787, CWE-798

More WatchGuard Technologies advisories

All WatchGuard Technologies

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.