A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.
Advisories
No advisories yet.
Fixes
Solution
Fireware OS 2026.2.2, Fireware OS 12.12.2, Fireware OS 12.5.20
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://psirt.watchguard.com/CVE-2026-13086 |
|
History
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code. | |
| Title | Fireware OS Stack-Based Buffer Overflow in Mobile Security epm Endpoint | |
| First Time appeared |
Watchguard
Watchguard fireware Os |
|
| Weaknesses | CWE-121 CWE-787 CWE-798 |
|
| CPEs | cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Watchguard
Watchguard fireware Os |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WatchGuard
Published:
Updated: 2026-08-27T23:24:32.779Z
Reserved: 2026-06-23T18:45:34.589Z
Link: CVE-2026-13086
No data.
Status : Received
Published: 2026-08-28T02:16:20.197
Modified: 2026-08-28T02:16:20.197
Link: CVE-2026-13086
No data.
OpenCVE Enrichment
No data.