CVE-2026-13728

MEDIUM

WatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resource Credential Database

Title source: cna
STIX 2.1

Description

In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2. This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster.

References (1)

Core 1
Core References

Scores

CVSS v3 4.4
EPSS 0.0013
EPSS Percentile 3.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-798
Status published
Products (3)
watchguard/fireware 12.1 - 12.12.1
WatchGuard/Fireware OS 12.1 - 12.12
WatchGuard/Fireware OS 2025.1 - 2026.2
Published Jul 03, 2026
Tracked Since Jul 03, 2026