Full-Time
Updated on 9/3/2026
Cybersecurity platform for managed service providers
No salary listed
Seattle, WA, USA
In Person
Bachelor's
See people who can refer or advise you
WatchGuard Technologies provides a Unified Security Platform designed for managed service providers. It offers integrated cybersecurity products that cover network security and intelligence, advanced endpoint protection, multi-factor authentication, and secure Wi-Fi, all managed through a single platform. The platform coordinates threat intelligence, policy management, automation, and reporting to help MSPs scale their security services, improve operational efficiency, and align security operations with their clients’ needs. The key differentiator is its MSP-focused approach, offering centralized control and automation across multiple security domains to simplify provisioning, management, and ongoing protection for thousands of resellers and hundreds of thousands of end customers. The company’s goal is to enable security resellers to grow their business while delivering robust protection and streamlined operations across global customers.
Company Size
1,001-5,000
Company Stage
IPO
Headquarters
Seattle, Washington
Founded
1996
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Flexible Work Hours
Remote Work Options
Health Insurance
Dental Insurance
Vision Insurance
Life Insurance
Disability Insurance
Health Savings Account/Flexible Spending Account
Paid Holidays
Paid Vacation
Paid Sick Leave
Paid Parental Leave
401(k) Retirement Plan
401(k) Company Match
Professional Development Budget
Adoption Assistance
Fertility Treatment Support
Childcare Support
WatchGuard fixes 4 critical Firebox RCE flaws. Last updated: August 28, 2026 4:58 am WatchGuard released three Fireware OS branches on August 27, 2026 to fix 11 security flaws, including four critical vulnerabilities rated 9.3. The company is telling customers and service providers to update every owned, managed, and client-operated Firebox immediately. The fixed versions are Fireware 2026.2.2, 12.12.2, and 12.5.20 for the older T15/T35 branch [1]. The most important boundary is that WatchGuard has not seen evidence of exploitation in the wild. That does not make the update optional: several flaws reach the IKE daemon before authentication, while another can give root code execution through a deprecated Mobile Security service from a trusted interface. A vulnerable version proves exposure to defective code, not that a Firebox was compromised. Which WatchGuard Firebox versions are affected? | Fireware branch | Affected and fixed versions | | Current default branch | Fireware OS 2025.0 through versions below 2026.2.2 are affected. Install 2026.2.2 or later. | | 12.x default branch | Fireware OS 12.0 through versions below 12.12.2 are affected. Install 12.12.2 or later. | | T15 and T35 appliances | Fireware OS 12.0 through versions below 12.5.20 are affected. Install 12.5.20 or later. | Do not infer safety from a disabled management Web UI alone. Most of the newly disclosed issues affect iked, the service that handles IKE and IPsec VPN traffic. One separate flaw affects epm, and another affects wgagent. Exposure depends on the service, interface, configuration, and CVE - not only whether the administrator page is public. Four critical RCE paths need different checks. * CVE-2026-19313: WatchGuard describes a pre-authentication heap overflow in iked. Crafted network traffic can crash the process, and attacker-controlled data written beyond the allocated buffer creates potential for remote code execution [2]. * CVE-2026-19315: two EAP payloads in a crafted IKE_AUTH message can trigger type confusion, an invalid-pointer free, and an iked crash. The detailed impact describes potential memory corruption and RCE beyond denial of service [3]. * CVE-2026-19318: an undersized length in an EAP-MSCHAPv2 payload can overflow a stack buffer after IKE_SA_INIT. This path requires IKE payload diagnostic logging to be enabled; disabling that troubleshooting option narrows this CVE but does not fix the other flaws [4]. * CVE-2026-13086: the deprecated Mobile Security feature exposes an epm JSON-RPC service. A network-adjacent attacker who can reach it through a trusted interface can overwrite a return address and run code as root without authentication [5]. The same firmware also fixes seven high-severity issues: CVE-2026-19314, CVE-2026-19316, CVE-2026-19317, CVE-2026-78008, CVE-2026-78009, CVE-2026-78010, and CVE-2026-78011. Most can disrupt IKE/IPsec VPN processing or another Fireware service; some detailed advisories discuss additional memory-corruption possibilities without confirming RCE. What Firebox administrators should do now. * Inventory the actual branch and appliance model. Record each Firebox version before the maintenance window. T15/T35 devices use the 12.5.20 fixed branch; do not copy a version number from a different model family. * Back up the configuration and install the vendor release. Obtain 2026.2.2, 12.12.2, or 12.5.20 from WatchGuard Cloud, the Firebox Web UI, or the official Software Downloads Center. Follow the release notes for the exact appliance and high-availability design. * Verify the result after reboot. Confirm the running version rather than relying on a completed download or queued upgrade. Test Branch Office VPN, Mobile VPN with IKEv2, and other production IPsec paths. * Check the two configuration-specific paths. Identify any appliance that still uses the deprecated Mobile Security feature, and check whether IKE payload diagnostic logging was enabled for troubleshooting. These findings change exposure analysis but do not replace the firmware update. * Review the pre-update window. Look for repeated iked, epm, or wgagent crashes and respawns, unexpected configuration or administrator changes, abnormal VPN failures, and unusual outbound connections. WatchGuard has not published a universal exploit IOC, so a clean keyword search cannot prove that the device was never targeted. * Escalate suspicious devices as incidents. Preserve logs and configuration, restrict network access, revoke suspect sessions, rotate privileged credentials from a known-clean system, and rebuild trust before returning a confirmed-compromised edge device to service. The response logic is similar to other exposed VPN gateways: patch status and incident status answer different questions. Gridinsoft's coverage of CVE-2026-33824 on Windows IKE VPN endpoints explains why UDP 500/4500 reachability matters, while the Citrix NetScaler response guide shows why an edge-device update should be followed by evidence review when exposure existed. References. * WatchGuard Technologies. "Immediate Action Required - Update Your Firebox Now." WatchGuard Product and Support News, August 27, 2026. Firmware releases and 11-CVE notice. * WatchGuard PSIRT. "CVE-2026-19313 - Fireware OS Pre-Authentication Heap Buffer Overflow in iked Allows Remote Code Execution." Published August 27, 2026. Affected versions and impact. * WatchGuard PSIRT. "CVE-2026-19315 - Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code Execution." Published August 27, 2026. IKE_AUTH condition and impact. * WatchGuard PSIRT. "CVE-2026-19318 - Fireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Code Execution." Published August 27, 2026. Diagnostic-logging condition. * WatchGuard PSIRT. "CVE-2026-13086 - Fireware OS Stack-Based Buffer Overflow in Mobile Security epm Endpoint." Published August 27, 2026. Trusted-interface root RCE path.
WatchGuard Agent for Windows Vulnerability allows code execution with elevated privileges. Spread the love WatchGuard has disclosed two critical vulnerabilities in its Windows-based WatchGuard Agent that could allow unauthenticated attackers to execute arbitrary code with elevated privileges. The flaws, tracked as CVE-2026-57910 and CVE-2026-57909, affect WatchGuard Agent versions earlier than 1.25.13.0000. The security issues were published on August 25, 2026. WatchGuard said it is not aware of either vulnerability being exploited in the wild at the time of disclosure. However, the severity and low attack complexity make prompt patching important for organizations running the affected endpoint protection component. CVE-2026-57910 has received a CVSS v4.0 score of 9.3 and is described as an improper authentication flaw. An unauthenticated attacker with network access could abuse the agent's UDP discovery and command service to trigger the TaskExecute event handler. The attack could cause the vulnerable agent to download and execute an attacker-controlled program. Since the WatchGuard Agent commonly operates with highly privileged permissions, successful exploitation could result in code execution as SYSTEM on Windows systems. This level of access would allow an attacker to install malware, alter security configurations, create persistence mechanisms, access sensitive files, and move further across an enterprise network. WatchGuard Agent for Windows Vulnerability. WatchGuard linked CVE-2026-57910 to several weakness categories, including missing authentication for a critical function, improper verification of cryptographic signatures, and downloading code without an integrity check. The combination suggests that the affected service did not sufficiently validate either the remote requester or the program it was instructed to retrieve and execute. The second issue, CVE-2026-57909, carries a CVSS v4.0 score of 9.4. It is a path traversal vulnerability that can allow an unauthenticated attacker on an adjacent network to execute arbitrary code on an affected WatchGuard Agent installation. According to WatchGuard, successful exploitation of CVE-2026-57909 could result in a complete loss of confidentiality, integrity, and availability of the affected endpoint protection component. The flaw stems from inadequate control over code generation and the absence of authentication for critical functionality, creating a path for attackers to bypass security controls and run malicious code remotely. Organizations should upgrade affected Windows deployments to WatchGuard Agent 1.25.13.0000 or later. WatchGuard also listed versions 1.17.02.0000 and 1.17.21.0000 as fixes for CVE-2026-57910, while CVE-2026-57909 requires version 1.25.13.0000. Security teams should identify all WatchGuard Agent installations, confirm their installed versions, and prioritize updates on systems exposed to untrusted or shared network segments. Until patching is complete, administrators should limit access to the agent's UDP discovery and command service through network segmentation and firewall rules. Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC The post WatchGuard Agent for Windows Vulnerability allows code execution with elevated privileges appeared first on cyber security News. WatchGuard has released urgent security updates to address multiple high-severity vulnerabilities affecting the WatchGuard Agent on Windows. The most critical of these flaws allows authenticated local attackers to escalate their privileges to the highest system level, granting them complete control over the compromised machine. Additional vulnerabilities discovered in the software... May 7, 2026 In "Cybersecurity News - Original News Source is cybersecuritynews.com" WatchGuard VPN Client Windows Vulnerability A security advisory addressing a significant privilege-escalation vulnerability affecting its Mobile VPN with an IPSec client for Windows. The flaw, identified as WGSA-2026-00002, allows local attackers to execute arbitrary commands with SYSTEM-level privileges, potentially granting them unrestricted access to the host machine. This vulnerability affects... February 5, 2026 In "Cybersecurity News - Original News Source is cybersecuritynews.com" A critical vulnerability in WatchGuard Firebox firewalls could allow attackers to gain complete administrative access to the devices without any authentication. The flaw, tracked as CVE-2025-59396, stems from insecure default configurations that expose SSH access on port 4118 using hardcoded credentials. WatchGuard Firebox appliances through September 10, 2025, ship with... November 11, 2025 In "Cybersecurity News - Original News Source is cybersecuritynews.com"
WatchGuard recognized as 2026 CRN Annual Report Card winner for Network Security. WatchGuard wins CRN's 2026 ARC Award for Network Security, recognizing its continued innovation, strong channel partnerships and commitment to partner success. 26 August 2026 By The Editor WatchGuard(R) Technologies, a global leader in unified cybersecurity, has been recognized as a 2026 CRN Annual Report Card (ARC) Award winner in the Security: Network Security - SMB category by CRN(R), a brand of The Channel Company. The recognition is based on direct feedback from solution providers across North America, who evaluated technology vendors on product innovation, support, partnership, and managed and cloud services. WatchGuard achieved an overall score of 92.8, ranking first in the category. The company received particularly strong scores for product innovation (95.4) and partnership (95.8), while also ranking first across all four evaluated areas. The CRN Annual Report Card Awards recognize technology vendors that demonstrate excellence in supporting and enabling their channel partners. The 2026 awards cover 23 technology categories and are based on evaluations from solution providers across North America. Advancing network security for distributed environments. The recognition comes as the network security landscape continues to evolve. Organizations increasingly need to protect users, devices and applications across traditional networks, cloud environments and remote locations, requiring security technologies that combine strong protection with greater visibility and simpler management. WatchGuard has continued to invest in its network security portfolio to address these changing requirements. Recent innovations include the expansion of Network Detection and Response (NDR) capabilities across the Firebox platform, enabling organizations to detect and respond to suspicious network behavior without deploying standalone NDR sensors. WatchGuard has also expanded its offering with Managed NDR and Total NDR, integrating network detection with ThreatSync(TM) XDR to provide broader security context and response capabilities. At the same time, FireCloud extends WatchGuard's network security capabilities into the cloud. FireCloud Total Access combines Secure Web Gateway, Firewall-as-a-Service and Zero Trust Network Access (ZTNA), helping organizations secure distributed users and provide identity- and device-aware access to private applications. Managed through WatchGuard Cloud, it also gives MSPs a scalable way to deliver cloud-based security across multiple customer environments. WatchGuard is also continuing to strengthen the performance and capabilities of its Firebox platform, including the introduction of its high-performance Firebox rackmount appliances for demanding network environments. Together, these developments reflect WatchGuard's broader evolution of network security - from traditional perimeter protection toward an integrated approach spanning network infrastructure, threat detection, cloud security and Zero Trust access. Innovation designed for the channel. For WatchGuard, innovation is closely tied to the needs of its MSP and solution provider partners. The company designs its security technologies to be centrally managed, integrated and scalable, helping partners deliver advanced protection without adding unnecessary operational complexity. The 2026 CRN ARC recognition provides external validation of this approach. Solution providers ranked WatchGuard highly not only for its product innovation, but also for its partnership, support and managed and cloud services. As organizations continue to adapt to increasingly distributed IT environments, WatchGuard remains focused on helping its partners deliver security that is powerful enough to address evolving threats, integrated enough to provide greater visibility, and simple enough to manage at scale.
Upcoming compliance requirement for partners using its apis. Featured Image Important notification! Due to export license and regulatory requirements, WatchGuard Technologies, Inc. need to make sure every subscriber account has complete data to enforce geographic controls. If you are currently using its Accounts API, you will need to implement some changes before September 17th to avoid disruption. The following data will be mandatory for all the subscribers: * Company name * Industry * First name * Last name * Full mailing address Now, activating or allocating licenses of any Watchguard product requires this information is previously added in the account information for every customer. To help partners manage these new requirements at scale, WatchGuard Technologies, Inc. has release a new version of the Accounts Public API available here, which partners can leverage bulk updates to their account information. If you are currently using its Accounts API, adding this data requires you to use the new Accounts API available here. The current version of the Accounts API will be deprecated on September 17th. Starting August 6th, the Allocations API will return a warning if a subscriber account is missing any required data. Starting September 17th, allocations will fail for accounts that haven't been updated. Further details about the changes to implement are available in this article. Once the required changes are implemented, the Allocations API will return a 200 Success status. Please ensure this is confirmed for all your accounts before September 17th to avoid disruption.
WatchGuard Technologies has appointed Vincent Hwang as chief product officer. Hwang will report to CEO Joe Smolarski and lead the company's platform and AI innovation strategies. Hwang brings over 20 years of cybersecurity experience from companies including Fortinet, Cisco, and Bitdefender. Most recently, he led Fortinet's Cloud Security business, achieving double-digit growth. At Bitdefender, he served as CPO, overseeing global product management and engineering. In his new role, Hwang will focus on developing enterprise-grade security solutions for managed service providers serving the midmarket. The appointment comes as WatchGuard aims to help partners simplify operations and reduce tool sprawl. WatchGuard provides unified cybersecurity solutions to over 25,000 managed service providers protecting more than 1.5 million customers worldwide.