ZeroHour

CVE-2026-78008

large

Buffer overflow in WatchGuard Fireware OS Management Web UI enables DoS or code execution

CVSS 4.0
8.6 high
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-78008 is a buffer overflow (out-of-bounds write, CWE-787) in the Management Web UI of WatchGuard's Fireware OS, the operating system that runs on the company's Firebox firewall appliances. An attacker who is already an authenticated administrator and has network access to the management interface can send specially crafted traffic that overflows a buffer, crashing the device or, in some conditions, executing arbitrary code. Because CVSS 4.0 rates this with high privileges required (PR:H) and unchanged scope, the impact is confined to the appliance itself and the attacker must already hold administrator credentials, for example through a compromised, reused, or leaked admin account. All Firebox deployments running a vulnerable Fireware OS release with the management Web UI reachable are affected; the available data does not specify which version ranges are vulnerable, so defenders should consult WatchGuard's advisory for the affected and fixed releases. There is currently no evidence of exploitation: the flaw is not in CISA's KEV, no public proof of concept is known, and EPSS assigns roughly a 0.4% chance of exploitation within 30 days (30th percentile).

What to do: Review WatchGuard's security advisory for CVE-2026-78008 to identify affected and fixed Fireware OS releases and upgrade each Firebox accordingly. As interim mitigation, restrict the Management Web UI to trusted administrative networks (dedicated management interface or interface access rules), avoid exposing it to the WAN, and audit which accounts hold administrator rights, enforcing strong credentials and MFA where available. Since no exploitation is known and no PoC is public, this fits a normal patch cycle, but check appliance logs for unexpected restarts or admin-account anomalies in the meantime.

Affected
WatchGuard Fireware OS — Management Web UI component (runs on Firebox appliances)
Estimated exposure
large≈ hundreds of thousands of Firebox appliances deployed, with the practically exploitable subset (management Web UI reachable plus valid admin credentials)… — WatchGuard Firebox firewalls are widely deployed at SMB and mid-market sites with an installed base on the order of hundreds of thousands of units, and internet-wide scans have repeatedly shown tens to hundreds of thousands of WatchGuard…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A buffer overflow vulnerability in the WatchGuard Fireware OS Management Web UI allows an authenticated administrator with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic.

Weakness
CWE-787
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.