216.73.217.22

CVE-2026-3987

· Published 01/04/2026 22:16 · Modified 01/04/2026 22:16

Labels: CVE-2026-3987 2026-04-015d1c2695-1a31-4499-88ae-e847036fd7e3CVE-2026-3987CWE-22

Essential information

Published
01/04/2026 22:16
Modified
01/04/2026 22:16
Author
Creator
CVSS
8.6 HIGH (v3) 8.6 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an elevated system process.This issue affects Fireware OS 12.6.1 up to and including 12.11.8 and 2025.1 up to and including 2026.1.2.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
5d1c2695-1a31-4499-88ae-e847036fd7e3
NVD
View on NVD

Affected products (CPE)

ProductCPE
watchguard / fireware os cpe:2.3:a:watchguard:fireware_os:12.6.1-12.11.8:*:*:*:*:*:*:*
watchguard / fireware os cpe:2.3:a:watchguard:fireware_os:2025.1-2026.1.2:*:*:*:*:*:*:*

References