Skip to main content

WatchGuard vulnerabilities in Fireware and Dimension: the perimeter also needs patching

The INCIBE-2026-593 advisory identifies WatchGuard vulnerabilities affecting Fireware and Dimension. When the flaw resides in the firewall or its management platform, the device protecting the network becomes the target.

CybersecuritySeintec team2-3 min read
WatchGuard vulnerabilities in Fireware and Dimension: the perimeter also needs patching

News summary

INCIBE published advisory INCIBE-2026-593 regarding vulnerabilities affecting the Fireware system and the Dimension visibility platform from the manufacturer WatchGuard. The general recommendation remains the standard and most effective one: apply the corrected versions released by the manufacturer.

A perimeter firewall possesses a characteristic that makes it particularly attractive to an attacker: it is, by definition, exposed to the internet and, simultaneously, maintains visibility and control over internal traffic. Compromising it bypasses the need to navigate the rest of the defences.

In our experience, the issue is usually not a lack of awareness regarding the advisory, but rather the absence of a procedure. Perimeter firmware is updated when someone remembers, typically coinciding with another intervention, rather than within a cycle with a designated owner and schedule.

There is a second, less discussed issue: the management and reporting platform. It centralises credentials, configurations, and visibility for the entire security infrastructure, yet all too often it is installed once and never touched again. It should be treated with the same level of rigour as the firewall itself.

Alongside the update, three measures significantly reduce the attack surface: do not expose the device management to the internet, enable MFA for administrators, and review accounts and VPN portals that remained active from previous configurations.

One final methodological note: it is advisable to save the configuration before each update and verify afterwards that rules and tunnels continue to behave as expected. A successful update with a missing rule is also an incident.

Source: INCIBE — 31 August 2026

What happened

INCIBE published advisory INCIBE-2026-593 covering vulnerabilities affecting the Fireware system and the Dimension visibility platform from manufacturer WatchGuard. The recommendation is to apply the fixed versions published by the vendor.

A perimeter firewall is exposed to the internet by definition and, at the same time, has visibility and control over internal traffic. Compromising it avoids having to get past the rest of the defences.

What it teaches a mid-sized business

The usual problem isn't unawareness of the advisory, but the lack of a procedure: perimeter firmware gets updated whenever someone remembers, without an owned cycle with a date.

The management and reporting platform concentrates credentials, configurations and visibility over the whole security infrastructure, and is often installed once and never touched again; it should be treated with the same rigour as the firewall itself.

What to review

Measures that greatly reduce the exposed surface:

  • Do not expose the device's administration on the internet.
  • Enable MFA for all administrators of the firewall and the management platform.
  • Review accounts and VPN portals left enabled from earlier configurations.
  • Save the configuration before each update and verify rules and tunnels afterwards.

Frequently Asked Questions

How often should firewall firmware be updated?
On a planned cycle of at least every quarter, and immediately whenever the vendor publishes a high- or critical-severity fix affecting your version.
Is it risky to update the perimeter in case connectivity is lost?
The risk is manageable: a prior configuration backup, an agreed window, an alternative access route available, and post-update verification of rules and tunnels.
Which WatchGuard components are affected?
The Fireware system and the Dimension visibility platform, according to advisory INCIBE-2026-593.

Concepts mentioned in this article: Firewall

The perimeter requires a maintenance cycle with a designated lead and date, not ad hoc interventions. At Seintec, we handle the patching, configuration, and monitoring of your security infrastructure. Speak with our team.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.