CVE-2026-3344 PUBLISHED

WatchGuard Firebox System Integrity Check Bypass

Assigner: WatchGuard
Reserved: 27.02.2026 Published: 03.03.2026 Updated: 03.03.2026

A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and maintain limited persistence via a maliciously-crafted firmware update package.This issue affects Fireware OS 12.0 up to and including 12.11.7, 12.5.9 up to and including 12.5.16, and 2025.1 up to and including 2026.1.1.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor WatchGuard
Product Fireware OS
Versions Default: unaffected
  • affected from 12.0 to 12.11.7 (incl.)
  • affected from 12.5.9 to 12.5.16 (incl.)
  • affected from 2025.1 to 2026.1.1 (incl.)

Exploits

WatchGuard is not aware of any exploitation of this issue in the wild.

References

Problem Types

  • CWE-440: Expected Behavior Violation CWE

Impacts

  • CAPEC-184 Software Integrity Attack