Skip to content

WatchGuard Technologies Fireware OS: cross-site scripting

Medium4.8CVE-2026-13375 · Published Jul 3, 2026 · updated Aug 28, 2026

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13938. This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.

Affected versions

PackageAffectedFixed in
Fireware OS
Product
>= 2025.1, < 2026.2.12026.2.1
>= 12.4, < 12.12.112.12.1
>= 2025.1, <= 2026.2No fix yet
>= 12.4, < 12.11.912.11.9
>= 12.4, < 12.5.1912.5.19
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-79

More WatchGuard Technologies advisories

All WatchGuard Technologies
Advisory
WatchGuard Technologies Fireware OS: improper signature check
High8.6Jul 3
WatchGuard Technologies Fireware OS: hard-coded credentials
Medium5.9Jul 3
WatchGuard Technologies Fireware OS: out-of-bounds write
High7.7Jul 3
WatchGuard Technologies Fireware OS: denial of service
Medium6.9Jul 3
WatchGuard Technologies Fireware OS: cross-site scripting
Medium4.8Jul 3
WatchGuard Technologies Fireware OS: cross-site scripting
Medium4.8Jul 3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.