{"total":3,"items":[{"id":521,"title":"ZDI-26-750: WatchGuard FireWare OS spamd statushdlr Stack-based Buffer Overflow Remote Code Execution Vulnerability","original_title":"ZDI-26-750: WatchGuard FireWare OS spamd statushdlr Stack-based Buffer Overflow Remote Code Execution Vulnerability","source_rating":null,"summary":"This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has…","ai":false,"actions":[],"url":"http://www.zerodayinitiative.com/advisories/ZDI-26-750/","type":"advisory","language":"en","published_at":"2026-09-30T05:00:00+00:00","severity":"laag","priority":8,"vendors":["WatchGuard"],"cves":[{"id":"CVE-2026-18145","cvss":8.6,"epss":0.00342,"epss_percentile":0.25275,"in_kev":false,"kev_ransomware":false}],"cve_count":1,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":8.6,"epss_max":0.00342,"source_count":1,"ncsc":null,"source":{"slug":"zdi","name":"Zero Day Initiative","category":"vulnerability","country":null,"license":"© Trend Micro Zero Day Initiative","reuse":"excerpt"},"bundle":null},{"id":522,"title":"ZDI-26-749: WatchGuard FireWare OS samld SAMLSession Deserialization of Untrusted Data Remote Code Execution Vulnerability","original_title":"ZDI-26-749: WatchGuard FireWare OS samld SAMLSession Deserialization of Untrusted Data Remote Code Execution Vulnerability","source_rating":null,"summary":"This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. An attacker must first obtain the ability to write to the samld session…","ai":false,"actions":[],"url":"http://www.zerodayinitiative.com/advisories/ZDI-26-749/","type":"advisory","language":"en","published_at":"2026-09-30T05:00:00+00:00","severity":"laag","priority":8,"vendors":["WatchGuard"],"cves":[{"id":"CVE-2026-13046","cvss":7.5,"epss":0.00324,"epss_percentile":0.23123,"in_kev":false,"kev_ransomware":false}],"cve_count":1,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":7.5,"epss_max":0.00324,"source_count":1,"ncsc":null,"source":{"slug":"zdi","name":"Zero Day Initiative","category":"vulnerability","country":null,"license":"© Trend Micro Zero Day Initiative","reuse":"excerpt"},"bundle":null},{"id":77,"title":"Warning: Two critical vulnerabilities which can lead to Remote Code Execution in WatchGuard, Patch Immediately!","original_title":"Warning: Two critical vulnerabilities which can lead to Remote Code Execution in WatchGuard, Patch Immediately!","source_rating":null,"summary":"","ai":false,"actions":[],"url":"https://ccb.belgium.be/advisories/warning-two-critical-vulnerabilities-which-can-lead-remote-code-execution-watchguard","type":"advisory","language":"en","published_at":"2026-09-29T18:20:00+00:00","severity":"laag","priority":20,"vendors":["WatchGuard"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"ccb-be","name":"CCB / Safeonweb@work (België)","category":"overheid","country":"BE","license":"© CCB, hergebruik voorbehouden","reuse":"link"},"bundle":null}]}