ZDI-26-632: WatchGuard FireWare OS epm connect Stack-based Buffer Overflow Remote Code Execution Vulnerability
ZDI disclosed a CVSS 8.8 unauthenticated stack-based buffer overflow in WatchGuard FireWare OS epm connect enabling network-adjacent remote code execution.
ZDI published advisory ZDI-26-632 for a stack-based buffer overflow in the epm connect component of WatchGuard FireWare OS. Network-adjacent attackers can execute arbitrary code without authentication. ZDI assigned CVSS 8.8 and the issue is tracked as CVE-2026-13086.
- Remote code execution in WatchGuard FireWare OS
- Pre-authentication, network-adjacent attack vector
- ZDI rated the issue CVSS 8.8
- Tracked as CVE-2026-13086
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-13086 | Unauthenticated Stack Buffer Overflow RCE in WatchGuard Fireware OS epm Service CVE-2026-13086 is a stack-based buffer overflow (CWE-121, CWE-787) in the epm (Endpoint Protection Manager) service of WatchGuard Fireware OS, tied to the now-deprecated Mobile Security feature; the advisory also associates CWE-798 (hard-coded credentials) with the finding. An unauthenticated remote attacker can trigger the overflow via the epm service (per ZDI-26-632, through a 'connect' request), gaining the ability to execute arbitrary code with the privileges of that service on the Firebox appliance. Impact is rated critical (CVSS 4.0: 9.3), with network attack vector, no privileges or user interaction required, and high loss of confidentiality, integrity, and availability on the compromised system. Affected organizations are WatchGuard Firebox users whose Fireware OS still exposes the deprecated Mobile Security (epm) component; deployments that have disabled or removed that feature are not exposed to this service. No public proof-of-concept is known, the flaw is not yet in CISA KEV, and EPSS currently assigns a low 0.4% probability of exploitation within 30 days, though the ZDI advisory makes the issue publicly disclosed. Do: Check whether Mobile Security/epm is enabled on your Fireboxes and whether the epm service is reachable from untrusted networks (management or external interfaces), and restrict access to it via firewall policy until patched. Apply the Fireware OS fix referenced in WatchGuard's advisory/ZDI-26-632 for your appliance's version line once confirmed, since specific fixed version numbers were not included in this data. Monitor WatchGuard's security portal for updates, as public disclosure via ZDI increases the likelihood of exploit development. | 9.3 | <1% |
| moderatelikely on the order of thousands to low tens of thousands of Firebox appliances with the deprecated Mobile Security (epm) service exposed (subset of… |
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-13086.
This source does not provide full text. Read it at zerodayinitiative.com.