Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Remote Code Execution Vulnerability (CVE-2026-13046) in WatchGuard FireWare OS Samld Service

A deserialization issue in WatchGuard FireWare OS's samld component (CVE‑2026‑13046) allows remote code execution if an attacker can write to the session directory. The flaw scores 7.5 CVSS and highlights the need for robust patch management and evidence of remediation for audit readiness.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
5 recommended
📰
Source
zerodayinitiative.com

Critical Remote Code Execution in WatchGuard FireWare OS Samld Service (CVE‑2026‑13046)

What It Is — A deserialization flaw in the samld component of WatchGuard FireWare OS permits an attacker who can write to the samld session directory to execute arbitrary code. The issue is rated CVSS 3.1 7.5 (high) with full confidentiality, integrity, and availability impact.

Exploitability — No public exploit code is known; exploitation requires the ability to write to the session directory, which may be achieved through additional vulnerabilities. Attack complexity is high, but the impact is severe.

Affected Products — WatchGuard FireWare OS (all versions prior to the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Underscores the importance of continuous vulnerability management and demonstrable, timely patching to satisfy control objectives for secure configuration.
  • Shows how unchecked input handling can compromise a core security service, eroding the integrity of audit logs and evidence.
  • Provides a concrete scenario for organizations to prove they have documented remediation workflows and monitoring that meet multiple framework requirements.

Recommended Actions

  • Apply the September 2026 WatchGuard patch without delay.
  • Restrict permissions on the samld session directory to the service account only.
  • Record the patch deployment and permission changes in your vulnerability‑management system for audit evidence.
  • Enable file‑integrity monitoring on the session directory to detect unauthorized modifications.
  • Update your control‑mapping documentation to reflect remediation of the “secure configuration” objective.

Source: Zero Day Initiative Advisory

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-749/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →