Description
A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Fireware OS 2026.2.2, Fireware OS 12.12.2, Fireware OS 12.5.20
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://psirt.watchguard.com/CVE-2026-13086 |
|
History
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code. | |
| Title | Fireware OS Stack-Based Buffer Overflow in Mobile Security epm Endpoint | |
| First Time appeared |
Watchguard
Watchguard fireware Os |
|
| Weaknesses | CWE-121 CWE-787 CWE-798 |
|
| CPEs | cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Watchguard
Watchguard fireware Os |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: WatchGuard
Published:
Updated: 2026-08-27T23:24:32.779Z
Reserved: 2026-06-23T18:45:34.589Z
Link: CVE-2026-13086
No data.
Status : Received
Published: 2026-08-28T02:16:20.197
Modified: 2026-08-28T02:16:20.197
Link: CVE-2026-13086
No data.
OpenCVE Enrichment
No data.