WatchGuard Dimension

17 known vulnerabilities in WatchGuard Dimension, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-86135 CVSS 7.0 high A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to…
  • CVE-2026-78618 CVSS 6.9 medium A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single…
  • CVE-2026-78617 CVSS 6.3 medium WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote…
  • CVE-2026-78616 CVSS 4.8 medium A Stored Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's Trusted CA certificate configuration allows an authenticated…
  • CVE-2026-78615 CVSS 4.6 medium A Reflected Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's report detail page allows an attacker to execute arbitrary…
  • CVE-2026-78614 CVSS 8.6 high WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user…
  • CVE-2026-78613 CVSS 8.6 high WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenticated user…
  • CVE-2026-78612 CVSS 8.6 high WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated…
  • CVE-2026-78610 CVSS 8.4 high WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an…
  • CVE-2026-78500 CVSS 5.1 medium A blind server-side request forgery (SSRF) vulnerability WatchGuard Dimension Database Server Test configuration allows an authenticated…
  • CVE-2026-78499 CVSS 5.1 medium A server-side request forgery (SSRF) vulnerability WatchGuard Dimension FTP Server Test configuration allows an authenticated privileged…
  • CVE-2026-78498 CVSS 5.1 medium A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Email Server Test configuration allows an authenticated privileged…
  • CVE-2026-78495 CVSS 5.3 medium A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Remote Backup Connection Test configuration allows an…
  • CVE-2026-78174 CVSS 9.3 critical WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension…
  • CVE-2026-78103 CVSS 5.1 medium WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The server-side configuration endpoint does not…
  • CVE-2026-78047 CVSS 5.1 medium A stored cross-site scripting (XSS) vulnerability in WatchGuard Dimension's task scheduling feature allows a low-privileged authenticated…
  • CVE-2026-13108 CVSS 8.7 high WatchGuard Dimension is susceptible to a denial-of-service condition when an attacker sends a high volume of TCP SYN packets to the log…