---
id: CVE-2026-4266
title: >-
  An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an
  attacker that has obtained write access to the local filesystem through
  another vulnerability to execute arbitrary code in the context of the portald
  user.


  No…
summary: >-
  An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an
  attacker that has obtained write access to the local filesystem through
  another vulnerability to execute arbitrary code in the context of the portald
  user.


  No…
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
vendor: watchguard
product: fireware
affected:
  - 'fireware >= 2025.1, < 2026.2'
  - 'fireware >= 12.1, < 12.12'
patched:
  - fireware 12.12
published: '2026-03-30'
updated: '2026-08-14'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-4266'
references:
  - url: 'https://psirt.watchguard.com/CVE-2026-4266'
    label: 5d1c2695-1a31-4499-88ae-e847036fd7e3
  - url: 'https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00007'
    label: 5d1c2695-1a31-4499-88ae-e847036fd7e3
tags:
  - nvd
epss: 0.0039
epssPercentile: 0.30405
ingestedAt: '2026-08-14T14:18:32.383Z'
---

## Overview

An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user.

Note, this vulnerability does not affect Firebox platforms that do not support the Access Portal feature, including the T15 and T35.

## Affected

- `fireware >= 2025.1, < 2026.2`
- `fireware >= 12.1, < 12.12`

## Remediation

Upgrade past the affected range:

- `fireware 12.12`
