Back to search
CVE-2026-3343
Published: Mar 3, 2026
Modified: Mar 4, 2026
PUBLISHED
Description
A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link. This vulnerability affects Fireware OS 12.7 up to and including 12.11.7 and 2025.1 up to and including 2026.1.1.
| Vendor | Product | Versions |
|---|---|---|
WatchGuard | Fireware OS | affected 12.7 - <= 12.11.7affected 2025.1 - <= 2026.1.1 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now