---
id: CVE-2026-13086
title: >-
  A stack-based buffer overflow in the epm (Endpoint Protection Manager) service
  used by the deprecated Mobile Security feature in WatchGuard Fireware OS
  allows an unauthenticated remote attacker to execute arbitrary code.
summary: >-
  A stack-based buffer overflow in the epm (Endpoint Protection Manager) service
  used by the deprecated Mobile Security feature in WatchGuard Fireware OS
  allows an unauthenticated remote attacker to execute arbitrary code.
severity: none
cwe:
  - CWE-121
  - CWE-787
  - CWE-798
published: '2026-08-28'
updated: '2026-08-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13086'
references:
  - url: 'https://psirt.watchguard.com/CVE-2026-13086'
    label: 5d1c2695-1a31-4499-88ae-e847036fd7e3
tags:
  - nvd
epss: 0.00441
epssPercentile: 0.37661
ingestedAt: '2026-08-29T21:42:36.531Z'
---

## Overview

A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
