Medium severity6.7NVD Advisory· Published Mar 30, 2026· Updated Aug 14, 2026
CVE-2026-4266
CVE-2026-4266
Description
An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user.
Note, this vulnerability does not affect Firebox platforms that do not support the Access Portal feature, including the T15 and T35.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*range: >=2025.1,<2026.2
- (no CPE)
- (no CPE)range: 12.1
Patches
Vulnerability mechanics
References
2- www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00007nvdVendor Advisory
- psirt.watchguard.com/CVE-2026-4266nvdBroken Link
News mentions
0No linked articles in our index yet.