AI analysis
CVE-2026-13086 is a stack-based buffer overflow (CWE-121, CWE-787) in the epm (Endpoint Protection Manager) service of WatchGuard Fireware OS, tied to the now-deprecated Mobile Security feature; the advisory also associates CWE-798 (hard-coded credentials) with the finding. An unauthenticated remote attacker can trigger the overflow via the epm service (per ZDI-26-632, through a 'connect' request), gaining the ability to execute arbitrary code with the privileges of that service on the Firebox appliance. Impact is rated critical (CVSS 4.0: 9.3), with network attack vector, no privileges or user interaction required, and high loss of confidentiality, integrity, and availability on the compromised system. Affected organizations are WatchGuard Firebox users whose Fireware OS still exposes the deprecated Mobile Security (epm) component; deployments that have disabled or removed that feature are not exposed to this service. No public proof-of-concept is known, the flaw is not yet in CISA KEV, and EPSS currently assigns a low 0.4% probability of exploitation within 30 days, though the ZDI advisory makes the issue publicly disclosed.
What to do: Check whether Mobile Security/epm is enabled on your Fireboxes and whether the epm service is reachable from untrusted networks (management or external interfaces), and restrict access to it via firewall policy until patched. Apply the Fireware OS fix referenced in WatchGuard's advisory/ZDI-26-632 for your appliance's version line once confirmed, since specific fixed version numbers were not included in this data. Monitor WatchGuard's security portal for updates, as public disclosure via ZDI increases the likelihood of exploit development.
Affected
| WatchGuard Fireware OS (epm / Endpoint Protection Manager service, deprecated Mobile Security feature) | — |
Estimated exposure
moderatelikely on the order of thousands to low tens of thousands of Firebox appliances with the deprecated Mobile Security (epm) service exposed (subset of… — WatchGuard's overall Firebox installed base is large (hundreds of thousands of appliances), but exposure is limited to deployments still running/exposing the deprecated Mobile Security epm service, which should be a minority subset; no…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.