{"id":"CVE-2026-3987","title":"A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an elevated system process.","summary":"A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an elevated system process.","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-22"],"vendor":"watchguard","product":"fireware","affected":["fireware >= 2025.1, < 2026.2","fireware >= 12.6.1, < 12.12"],"patched":["fireware 12.12"],"published":"2026-04-01","updated":"2026-08-14","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-3987","references":[{"url":"https://psirt.watchguard.com/CVE-2026-3987","label":"5d1c2695-1a31-4499-88ae-e847036fd7e3"},{"url":"https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00009","label":"5d1c2695-1a31-4499-88ae-e847036fd7e3"}],"tags":["nvd"],"epss":0.00679,"epssPercentile":0.50928,"ingestedAt":"2026-08-14T14:18:32.578Z","slug":"CVE-2026-3987","body":"## Overview\n\nA path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an elevated system process.\n\n## Affected\n\n- `fireware >= 2025.1, < 2026.2`\n- `fireware >= 12.6.1, < 12.12`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `fireware 12.12`","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":39.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}