MEDIUM
WatchGuard Firebox System Integrity Check Bypass
Published Mar 3, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.45%
Description
A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and maintain limited persistence via a maliciously-crafted firmware update package.
Affected products
-
- Version 12.0StatusaffectedConstraints<12.11.8
- Version 12.0StatusaffectedConstraints<12.5.17
- Version 2025.1StatusaffectedConstraints<2026.1.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| WatchGuard | Fireware OS | unaffected |
|
Configuration 1
AND
- ≥ 12.0 · < 12.11.8
Running on/with
OR
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 2
AND
- ≥ 12.5.9 · < 12.5.17
Running on/with
OR
- n/a
- n/a
Configuration 3
AND
- ≥ 2025.1 · < 2026.1.2
Running on/with
OR
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Fireware OS 2026.1.2, Fireware OS 12.11.8, Fireware OS 12.5.17
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-9290 Advisory
- https://psirt.watchguard.com/CVE-2026-3344 vendor-advisory
- https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00005 vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-9290 | Advisory | |
| https://psirt.watchguard.com/CVE-2026-3344 | vendor-advisory | |
| https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00005 | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WatchGuard
Published Mar 3, 2026
Updated Aug 10, 2026
Reserved Feb 27, 2026
Link CVE-2026-3344
CISA Vulnrichment
Updated Mar 3, 2026
ENISA EUVD
EUVD-2026-9290 Assigner WatchGuard
Published Mar 3, 2026
Updated Aug 10, 2026
Exploited since n/a
Link EUVD-2026-9290