WatchGuard vulnerabilities in Fireware and Dimension: the perimeter also needs patching
The INCIBE-2026-593 advisory identifies WatchGuard vulnerabilities affecting Fireware and Dimension. When the flaw resides in the firewall or its management platform, the device protecting the network becomes the target.

News summary
INCIBE published advisory INCIBE-2026-593 regarding vulnerabilities affecting the Fireware system and the Dimension visibility platform from the manufacturer WatchGuard. The general recommendation remains the standard and most effective one: apply the corrected versions released by the manufacturer.
A perimeter firewall possesses a characteristic that makes it particularly attractive to an attacker: it is, by definition, exposed to the internet and, simultaneously, maintains visibility and control over internal traffic. Compromising it bypasses the need to navigate the rest of the defences.
In our experience, the issue is usually not a lack of awareness regarding the advisory, but rather the absence of a procedure. Perimeter firmware is updated when someone remembers, typically coinciding with another intervention, rather than within a cycle with a designated owner and schedule.
There is a second, less discussed issue: the management and reporting platform. It centralises credentials, configurations, and visibility for the entire security infrastructure, yet all too often it is installed once and never touched again. It should be treated with the same level of rigour as the firewall itself.
Alongside the update, three measures significantly reduce the attack surface: do not expose the device management to the internet, enable MFA for administrators, and review accounts and VPN portals that remained active from previous configurations.
One final methodological note: it is advisable to save the configuration before each update and verify afterwards that rules and tunnels continue to behave as expected. A successful update with a missing rule is also an incident.
Source: INCIBE — 31 August 2026
Why this matters to a company operating in Spain
The threat landscape affecting Spanish companies no longer distinguishes by size. Attacks are automated, sold as a service, and seek the shortest path: a reused credential, an unpatched server, or a provider with poorly controlled remote access. For an SME, the difference between a minor scare and a multi-day shutdown almost always depends on decisions made before the incident.
That is why every industry update should be read in operational terms: which specific controls would have prevented the problem, what evidence must be preserved, and who makes the decision when the clock is ticking. This is the approach we apply to managed cybersecurity projects at Seintec.
Real business impact
Before deciding on an investment, it is advisable to identify what is at stake. In cybersecurity projects, we typically review these four areas with management and the IT manager:
- Operational disruption: orders, invoicing, or production halted while systems are restored.
- Loss or exposure of personal data, with a mandatory 72-hour notification requirement to the AEPD.
- Hidden cost of recovery: overtime, external hiring, and loss of client trust.
- Contractual and compliance requirements (ENS, NIS2, ISO 27001) that demand evidence, not intentions.
Five-step action plan
A useful plan fits on one page. This is the roadmap we apply with our clients to move from news to measurable improvement, without disrupting daily operations:
- Identify all affected devices and management platforms, including remote sites.
- Check the firmware version against the patched versions published by the manufacturer.
- Remove any management interfaces from the internet and enable MFA for administrators.
- Update during a planned window with backed-up configuration and a roll-back plan.
- Afterwards, review rules, VPN tunnels, and legacy accounts that are no longer in use.
Key indicators you should be measuring
What is not measured is not managed. These indicators allow you to verify if the technological investment is yielding results and serve as the basis for the periodic reports we deliver to our clients:
- Percentage of perimeter devices with updated and supported firmware.
- Number of management interfaces accessible from the internet.
- Average days between the publication of a notice and the application of the patch.
- Active management accounts versus actual administrators.
How we approach it at Seintec: Cybersecurity
We shield your business so it never stops. We operate from our own datacenter in Spain, with a certified technical team and a single point of contact who knows your infrastructure, so you do not have to explain your environment every time an incident arises.
These are the capabilities we bring to the table in a cybersecurity project:
- EDR / XDR: Advanced detection and response across endpoints and network.
- UTM perimeter security: Managed firewall and segmentation.
- Email filtering: Blocking of phishing, spam, and impersonation.
- WAF: Protection of published applications and services.
- Immutable backup: Backups that ransomware cannot alter.
- MFA and identity: Conditional access by user and device.
What you gain by working with a technology partner
Outsourcing does not mean losing control: it means gaining predictability, coverage, and independent technical insight. These are the benefits our clients highlight:
- Total prevent–detect–respond coverage: Immutable backup, email filtering, WAF, EDR/XDR and UTM perimeter security in a single managed contract.
- Assured continuity: Regain control of your infrastructure following a cyber incident with a recovery objective agreed with you in the continuity plan.
- Zero Trust by design: Identity-based access control and MFA for every user and device.
- AI-powered defence: Machine learning engines that monitor endpoints and networks in real time, reducing the mean time to detection.
Frequently Asked Questions
- How often should firewall firmware be updated?
- With a planned quarterly cycle as a minimum, and immediately when the manufacturer releases a high or critical severity patch affecting your version.
- Is updating the perimeter dangerous in case connectivity is lost?
- Risk is managed: prior configuration backup, agreed window, alternative access available, and subsequent verification of rules and tunnels. It is a much lower risk than operating with a known vulnerability.
- How do I know if my company is truly protected?
- With evidence: EDR coverage, two-factor authentication on all remote access, immutable copies, and a recently tested restoration. If any of these four points are not confirmed, there is a real risk of prolonged downtime.
- Where should a company wanting to address cybersecurity begin?
- With an audit of the current environment. At Seintec, we perform an initial no-cost review that identifies risks, dependencies, and priorities, resulting in a phased plan with fixed deadlines and budgets.
- Is it necessary to halt business operations during the project?
- No. We plan migrations and changes within agreed windows, with prior pilot tests and rollback options, ensuring disruption is minimal or non-existent for users.
- What type of companies do you serve?
- SMEs and mid-market companies in sectors such as industry, automotive, logistics, retail, legal, and healthcare, with both on-premises and hybrid cloud infrastructure.
- What coverage and response times (SLA) do you offer?
- Support from Monday to Friday, 09:00 to 18:00, and 24x7 emergencies 365 days a year, with a committed response SLA and a 99.98% service SLA in 2025.
Concepts mentioned in this article: Firewall
The perimeter requires a maintenance cycle with a designated lead and date, not ad hoc interventions. At Seintec, we handle the patching, configuration, and monitoring of your security infrastructure. Speak with our team.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.