Key takeaways
- WatchGuard’s August 27 advisories identify fixes in Fireware OS 2026.2.2, 12.12.2, and 12.5.20, plus Dimension 2.3.1.
- The affected Fireware release depends on platform: default Fireware builds and T15/T35 appliances have different fixed-version thresholds.
- WatchGuard advisories include critical-rated issues involving Fireware services and a critical Dimension issue involving administrator-session exposure in diagnostic logs.
- Inventory should include Firebox model, installed Fireware version, enabled services, external exposure, and the associated Dimension deployment.
- Use normal change-control practices: back up configurations, review release documentation, schedule maintenance, validate VPN and policy operation, and confirm the installed version after the update.
Canadian advisory follows WatchGuard’s August 27 disclosures
The Canadian Centre for Cyber Security published advisory AV26-865 on August 31, 2026, warning that WatchGuard Dimension releases before 2.3.1 and specified Fireware OS versions are affected by vulnerabilities. The advisory directs administrators to review WatchGuard’s security information and apply available updates.
WatchGuard’s own PSIRT portal shows a group of Fireware OS and Dimension CVEs published on August 27. The vendor’s listings identify Fireware OS 2026.2.2, 12.12.2, and 12.5.20 as fixed releases for the newly published Fireware issues, while Dimension 2.3.1 is the fixed release for the newly listed Dimension issues. ([cyber.gc.ca](https://www.cyber.gc.ca/en/alerts-advisories/watchguard-security-advisory-av26-865?utm_source=openai))
Confirm the correct Fireware OS release train
Administrators should not treat the three Fireware versions as interchangeable. WatchGuard identifies different affected ranges by platform. For its default Fireware OS train, the relevant advisories list versions from 2025.0 through before 2026.2.2, and versions from 12.0 through before 12.12.2. For T15 and T35 appliances, the affected range extends from 12.0 through before 12.5.20.
That distinction makes a device-and-version inventory the first practical step. Record each Firebox model, present Fireware OS version, location, management path and enabled VPN or remote-access services. Then match each appliance to WatchGuard’s affected-product table before setting an upgrade target. WatchGuard’s release-notes index also lists the 12.5.20 Fireware and 2.3.1 Dimension releases, providing a source to review before a maintenance window. ([psirt.watchguard.com](https://psirt.watchguard.com/CVE-2026-13086))
Critical issues raise the priority for exposed services
Among the Fireware advisories, CVE-2026-19315 is rated 9.3 under CVSS v4.0. WatchGuard describes it as a pre-authentication type-confusion flaw in the iked process that could allow a remote, unauthenticated attacker to execute arbitrary code with specially crafted network traffic. The affected-version and fixed-version tables align with the Fireware release thresholds identified in the Canadian advisory.
A second 9.3-rated issue, CVE-2026-13086, concerns the Endpoint Protection Manager service associated with the deprecated Mobile Security feature. WatchGuard states that an unauthenticated network-adjacent attacker with access to a trusted interface could execute arbitrary code through the service. For both CVEs, WatchGuard states it was not aware of exploitation in the wild when the advisories were published. ([psirt.watchguard.com](https://psirt.watchguard.com/CVE-2026-19315/))
Dimension systems require equal attention
The Dimension update is not merely a reporting-platform housekeeping task. WatchGuard’s PSIRT listings for Dimension 2.0 through before 2.3.1 include issues categorized as SQL injection, server-side request forgery, cross-site scripting, denial of service, access-control weaknesses and session-related flaws.
One of those reports, CVE-2026-78174, is rated 9.3. WatchGuard says a low-privileged Dimension Administrator could retrieve diagnostic logs containing unredacted session identifiers for a logged-in user and use those values to impersonate a Super Administrator. The vendor lists Dimension 2.3.1 as the solution and says it was not aware of active exploitation at publication. Organizations should therefore review who can reach Dimension, limit administrator roles to operational need, and avoid treating the server as a lower-priority internal appliance. ([psirt.watchguard.com](https://psirt.watchguard.com/))
A controlled remediation sequence for integrators
For integrators supporting dispersed sites, remediation should start with an inventory and exposure review rather than a blind, estate-wide firmware push. Prioritize appliances that provide site-to-site or remote-access VPN functions, have externally reachable administrative services, or sit at the edge of facilities where security, video, building systems or business networks share connectivity.
Before upgrading, preserve current configurations and document any local dependencies such as VPN interoperability, dynamic routing, authentication, logging and management connectivity. Carry out the vendor-supported update during an approved maintenance window, retain a rollback plan, and test critical traffic flows afterward. Confirm that each Firebox or Dimension system reports the intended fixed version; updating a management platform does not update connected Fireboxes, and vice versa.
The Canadian advisory does not report exploitation or prescribe a workaround in place of updating. Where an immediate update cannot be scheduled, teams should reduce unnecessary exposure to affected services, restrict management access to approved administrative networks, and elevate monitoring until the affected software is replaced. ([cyber.gc.ca](https://www.cyber.gc.ca/en/alerts-advisories/watchguard-security-advisory-av26-865?utm_source=openai))
Sources
- WatchGuard security advisory (AV26-865) — Canadian Centre for Cyber Security
- WatchGuard Security Advisories — WatchGuard Technologies
- CVE-2026-19315 — Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code Execution — WatchGuard Technologies
- CVE-2026-13086 — Fireware OS Stack-Based Buffer Overflow in Mobile Security epm Endpoint — WatchGuard Technologies
- CVE-2026-78174 — WatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic Logs — WatchGuard Technologies
- Fireware Release Notes — WatchGuard Technologies
