CVE-2026-13079

HIGH

WatchGuard Mobile VPN with SSL Windows Client Local Privilege Escalation

Title source: cna
STIX 2.1

Description

A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the machine where the client is installed. This issue affects the Mobile VPN with SSL client for Windows up to and including 2026.2.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 3.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-732
Status published
Products (4)
watchguard/fireware 12.0.0 - 12.12.1
WatchGuard/Fireware OS 12.0 - 12.12
WatchGuard/Fireware OS 2025.1 - 2026.2
watchguard/mobile_vpn_with_ssl < 2026.2.1
Published Jul 03, 2026
Tracked Since Jul 03, 2026