Vulnerability Description
In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Watchguard | Fireware | >= 12.1, < 12.12.1 |
| Watchguard | Firebox M270 | - |
| Watchguard | Firebox M290 | - |
| Watchguard | Firebox M370 | - |
| Watchguard | Firebox M390 | - |
| Watchguard | Firebox M440 | - |
| Watchguard | Firebox M4600 | - |
| Watchguard | Firebox M470 | - |
| Watchguard | Firebox M4800 | - |
| Watchguard | Firebox M5600 | - |
| Watchguard | Firebox M570 | - |
| Watchguard | Firebox M5800 | - |
| Watchguard | Firebox M590 | - |
| Watchguard | Firebox M670 | - |
| Watchguard | Firebox M690 | - |
| Watchguard | Firebox Nv5 | - |
| Watchguard | Firebox T20 | - |
| Watchguard | Firebox T25 | - |
| Watchguard | Firebox T40 | - |
| Watchguard | Firebox T45 | - |
Related Weaknesses (CWE)
References
- https://psirt.watchguard.com/CVE-2026-13728
- https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00025Vendor Advisory
FAQ
What is CVE-2026-13728?
CVE-2026-13728 is a vulnerability with a CVSS score of 4.4 (MEDIUM). In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability does not affect de...
How severe is CVE-2026-13728?
CVE-2026-13728 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-13728?
Check the references section above for vendor advisories and patch information. Affected products include: Watchguard Fireware, Watchguard Firebox M270, Watchguard Firebox M290, Watchguard Firebox M370, Watchguard Firebox M390.