WatchGuard TechnologiesCVE-2026-13086
WatchGuard Technologies Fireware OS: stack buffer overflow
Critical9.3CVE-2026-13086 · Published Aug 28, 2026 · updated Sep 3, 2026
A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Fireware OS Product | >= 2025.0, < 2026.2.2 | 2026.2.2 |
| >= 12.0, < 12.12.2 | 12.12.2 | |
| >= 2026.3, < 2026.3.1 | 2026.3.1 | |
| >= 12.0, < 12.5.20 | 12.5.20 |
Details and references
More WatchGuard Technologies advisories
All WatchGuard Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 28 | WatchGuard Technologies Dimension: SQL injection | High8.6 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: cross-site scripting | Medium4.6 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: cross-site scripting | Medium4.8 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: observable discrepancy | Medium6.3 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: improper access control | Medium6.9 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: server-side request forgery | Medium5.3 | 2.3.1 |