CVE-2026-4266 PUBLISHED

WatchGuard Firebox Insecure Deserialization in Fireware Access Portal

Assigner: WatchGuard
Reserved: 16.03.2026 Published: 30.03.2026 Updated: 30.03.2026

An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user.This issue affects Fireware OS: 12.1 through 12.11.8 and 2025.1 through 2026.1.2.

Note, this vulnerability does not affect Firebox platforms that do not support the Access Portal feature, including the T-15 and T-35.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.4

Product Status

Vendor WatchGuard
Product Fireware OS
Versions Default: unaffected
  • affected from 12.1 to 12.11.8 (incl.)
  • affected from 2025.1 to 2026.1.2 (incl.)

Exploits

WatchGuard is not aware of any exploitation of this issue in the wild.

Credits

  • btaol finder

References

Problem Types

  • CWE-502 Deserialization of Untrusted Data CWE

Impacts

  • CAPEC-253 Remote Code Inclusion