CVE-2026-13086 CRITICAL

CVE-2026-13086: Fireware OS Stack-Based Buffer Overflow in Mobile Security epm Endpoint

Vendor Watchguard
Product Fireware OS
Weakness CWE-121
Published August 27, 2026
Last update August 29, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.

Key dates

02Disclosure timeline

August 27, 2026 CVE published
August 29, 2026 Record updated