WatchGuard TechnologiesCVE-2026-13728
WatchGuard Technologies Fireware OS: hard-coded credentials
Medium5.9CVE-2026-13728 · Published Jul 3, 2026 · updated Aug 28, 2026
In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Fireware OS Product | >= 2025.1, < 2026.2.1 | 2026.2.1 |
| >= 12.0, < 12.12.1 | 12.12.1 | |
| >= 12.0, < 12.11.9 | 12.11.9 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-798
More WatchGuard Technologies advisories
All WatchGuard Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 3 | WatchGuard Technologies Fireware OS: improper signature check | High8.6 | 2026.2.1+2 more |
| Jul 3 | WatchGuard Technologies Fireware OS: out-of-bounds write | High7.7 | 2026.2.1+3 more |
| Jul 3 | WatchGuard Technologies Fireware OS: denial of service | Medium6.9 | 2026.2.1+3 more |
| Jul 3 | WatchGuard Technologies Fireware OS: cross-site scripting | Medium4.8 | 2026.2.1+3 more |
| Jul 3 | WatchGuard Technologies Fireware OS: cross-site scripting | Medium4.8 | 2026.2.1+3 more |
| Jul 3 | WatchGuard Technologies Fireware OS: cross-site scripting | Medium4.8 | 2026.2.1+3 more |