WatchGuard: 25 Vulnerabilities Disclosed, Including RCE in Fireware OS and SQLi in Dimension
WatchGuard disclosed 25 vulnerabilities on August 28, 2026, affecting Dimension and Fireware OS, including critical flaws with remote code execution potential.

Key findings
- 25 vulnerabilities disclosed on August 28, 2026, impacting WatchGuard Dimension and Fireware OS.
- Critical vulnerabilities in Fireware OS's
ikedprocess allow for remote code execution and DoS. - Multiple SQL injection and XSS flaws affect the WatchGuard Dimension management platform.
- Authenticated attackers can exploit Dimension vulnerabilities for command execution and account takeover.
- SSRF vulnerabilities in Dimension allow for network service enumeration.
- A CSRF vulnerability enables unauthorized passphrase changes for administrators.
On August 28, 2026, a significant batch of 25 vulnerabilities was disclosed for WatchGuard products, primarily affecting the Dimension management platform and the Fireware OS. This coordinated disclosure event includes a mix of critical, high, and medium severity flaws, with several critical vulnerabilities carrying the potential for remote code execution. The vulnerabilities span various attack vectors, including SQL injection, cross-site scripting (XSS), server-side request forgery (SSRF), buffer overflows, and business logic flaws, impacting both authenticated and unauthenticated users.
The WatchGuard Dimension platform is the most heavily impacted, with numerous vulnerabilities stemming from its web interface and administrative features. Three high-severity SQL injection vulnerabilities (CVE-2026-78613, CVE-2026-78612, CVE-2026-78614) were found in the audit report, log viewer, and scheduled report features, respectively. These flaws allow authenticated users with report administration permissions to gain arbitrary command execution. Additionally, a critical vulnerability (CVE-2026-78174) allows a low-privileged administrator to take over a Super Administrator's account by exploiting unredacted session identifiers in diagnostic logs. Other Dimension-related issues include stored and reflected XSS vulnerabilities (CVE-2026-78616, CVE-2026-78615, CVE-2026-7813) and a CSRF flaw in the administrator passphrase change action (CVE-2026-78610). Several SSRF vulnerabilities (CVE-2026-78500, CVE-2026-78499, CVE-2026-78498, CVE-2026-78495) were also identified in various test configurations, allowing attackers to enumerate network services.
The WatchGuard Fireware OS, particularly its VPN processing component, is affected by a cluster of high and critical severity vulnerabilities within the iked process. These include multiple buffer overflows (CVE-2026-78010, CVE-2026-19318), out-of-bounds reads (CVE-2026-78009, CVE-2026-19317), integer underflows (CVE-2026-78011, CVE-2026-19314), a double-free vulnerability (CVE-2026-19316), and a type confusion vulnerability (CVE-2026-19315). These flaws, exploitable by remote unauthenticated attackers, can lead to denial of service conditions or arbitrary code execution. A separate buffer overflow in the Management Web UI (CVE-2026-78008) also allows authenticated administrators to cause a DoS or potentially execute arbitrary code.
The breadth of these vulnerabilities underscores the importance of timely patching and security updates for WatchGuard products. While specific patch details were not provided in the disclosure, users are strongly advised to consult WatchGuard's official security advisories for the affected products and apply any available updates immediately to mitigate the risks associated with these critical flaws. The simultaneous disclosure of such a large number of vulnerabilities highlights a significant security event for WatchGuard users, necessitating a proactive approach to system security and vulnerability management.
The vulnerabilities disclosed on August 28, 2026, represent a critical security event for WatchGuard users. The concentration of high and critical severity flaws, including multiple remote code execution possibilities, demands immediate attention. Administrators should prioritize updating both WatchGuard Dimension and Fireware OS to the latest available versions to protect against these widespread security weaknesses.
Key findings include:
- 25 vulnerabilities disclosed on August 28, 2026, impacting WatchGuard Dimension and Fireware OS.
- Critical vulnerabilities in Fireware OS's
ikedprocess allow for remote code execution and DoS. - Multiple SQL injection and XSS flaws affect the WatchGuard Dimension management platform.
- Authenticated attackers can exploit Dimension vulnerabilities for command execution and account takeover.
- SSRF vulnerabilities in Dimension allow for network service enumeration.
- A CSRF vulnerability enables unauthorized passphrase changes for administrators.