Critical Remote Code Execution Vulnerability (CVE‑2026‑13086) in WatchGuard FireWare OS
What It Is – A stack‑based buffer overflow in the Endpoint Protection Manager (EPM) service of WatchGuard FireWare OS permits an unauthenticated, network‑adjacent attacker to execute arbitrary code with root privileges.
Exploitability – The flaw is remotely exploitable without authentication or user interaction. CVSS v3.1 base score 8.8 (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). No public exploit has been observed, but a proof‑of‑concept exists in the advisory.
Affected Products – WatchGuard FireWare OS (all versions prior to the September 2026 security update).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous vulnerability management and evidence that patches are applied promptly – a core control area across frameworks such as NIST CSF 2.0.
- Highlights the importance of maintaining an auditable configuration baseline for security‑critical infrastructure.
- Provides a concrete test of the “secure configuration and patch management” control objective that underpins trust in network‑edge devices.
Recommended Actions
- Deploy the WatchGuard patch released on 2026‑09‑09 to all FireWare OS instances.
- Verify the running version via automated inventory tools and record the patch status as compliance evidence.
- Enable and forward EPM service logs to a centralized SIEM for real‑time detection of anomalous activity.
- Conduct a focused vulnerability scan of all firewall assets to confirm remediation.
- Update your configuration‑management database (CMDB) to reflect the patched state and retain the change record for audit purposes.
Source: Zero Day Initiative Advisory – ZDI‑26‑632 (CVE‑2026‑13086)