VYPR
Medium severity6.7NVD Advisory· Published Mar 30, 2026· Updated Aug 14, 2026

CVE-2026-4266

CVE-2026-4266

Description

An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user.

Note, this vulnerability does not affect Firebox platforms that do not support the Access Portal feature, including the T15 and T35.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*range: >=2025.1,<2026.2
    • (no CPE)
    • (no CPE)range: 12.1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.