Critical Remote Code Execution in WatchGuard FireWare OS Samld Service (CVE‑2026‑13046)
What It Is — A deserialization flaw in the samld component of WatchGuard FireWare OS permits an attacker who can write to the samld session directory to execute arbitrary code. The issue is rated CVSS 3.1 7.5 (high) with full confidentiality, integrity, and availability impact.
Exploitability — No public exploit code is known; exploitation requires the ability to write to the session directory, which may be achieved through additional vulnerabilities. Attack complexity is high, but the impact is severe.
Affected Products — WatchGuard FireWare OS (all versions prior to the September 2026 security update).
Why It Matters for Trust & Control Assurance
- Underscores the importance of continuous vulnerability management and demonstrable, timely patching to satisfy control objectives for secure configuration.
- Shows how unchecked input handling can compromise a core security service, eroding the integrity of audit logs and evidence.
- Provides a concrete scenario for organizations to prove they have documented remediation workflows and monitoring that meet multiple framework requirements.
Recommended Actions
- Apply the September 2026 WatchGuard patch without delay.
- Restrict permissions on the
samldsession directory to the service account only. - Record the patch deployment and permission changes in your vulnerability‑management system for audit evidence.
- Enable file‑integrity monitoring on the session directory to detect unauthorized modifications.
- Update your control‑mapping documentation to reflect remediation of the “secure configuration” objective.
Source: Zero Day Initiative Advisory