CVE-2026-13079 HIGH

CVE-2026-13079: WatchGuard Mobile VPN with SSL Windows Client Local Privilege Escalation

Vendor Watchguard
Product Fireware OS
Weakness CWE-732
Published July 2, 2026
Last update July 7, 2026

CVSS base score

7.3/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L

What the vulnerability does

01Description

A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the machine where the client is installed. This issue affects the Mobile VPN with SSL client for Windows up to and including 2026.2.

Key dates

02Disclosure timeline

July 2, 2026 CVE published
July 7, 2026 Record updated