CVE-2026-78616

A Stored Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's Trusted CA certificate configuration allows an authenticated administrator to execute arbitrary JavaScript in another authenticated administrator's web browser by saving a carefully crafted certificate.

  • Published Aug 28, 2026
  • CVSS 4.8 medium
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-78616 at the National Vulnerability Database