Skip to content
ThreatCluster

Remote Code Execution Vulnerability in WatchGuard FireWare OS

First seen 30 Sep 2026, 21:37 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 22:31 UTC
  • •CVE-2026-13046 allows remote code execution on WatchGuard FireWare OS.
  • •Attackers must have write access to the samld session directory to exploit the vulnerability.
  • •WatchGuard has released a patch to address this issue as of September 30, 2026.

A remote code execution vulnerability has been identified in WatchGuard FireWare OS affecting its samld SAML session handling. Attackers who can write to the samld session directory can exploit this flaw, which arises from improper validation of user-supplied data leading to deserialization of untrusted data. The vulnerability has been assigned CVE-2026-13046, and WatchGuard has released an update to mitigate the issue. The advisory was publicly released on September 30, 2026, following a report to the vendor on May 22, 2026. The flaw allows attackers to execute arbitrary code in the context of the samld service, potentially leading to significant security breaches. Users are advised to apply the available patches immediately to protect their systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-05-22
Vulnerability reported to vendor
The vulnerability was disclosed to WatchGuard, prompting an investigation and subsequent patch development.
Zerodayinitiative
2026-09-30
Public advisory released
WatchGuard publicly disclosed the advisory for CVE-2026-13046, detailing the vulnerability and its impact.
psirt.watchguard.com
2026-09-30
Advisory updated
The advisory was updated with additional details about the vulnerability and mitigation steps.
Zerodayinitiative

More articles in this cluster (3)

Common questions

What systems are affected by this vulnerability?
The vulnerability affects installations of WatchGuard FireWare OS that utilize the samld service.
What should users do to protect their systems?
Users should apply the latest updates provided by WatchGuard to mitigate the vulnerability.
Is there any evidence of exploitation in the wild?
Currently, there is no confirmed evidence of exploitation in the wild for this vulnerability.