Executive brief
A vulnerability in WatchGuard Fireware OS could allow an unauthorized person to crash the firewall remotely. This affects devices using IKEv2 for Mobile User VPNs or Branch Office VPNs with dynamic gateways. If exploited, this would cause a denial-of-service, disrupting network connectivity and VPN access for the entire organization.
Technical details
A NULL pointer dereference vulnerability exists in the 'iked' process of WatchGuard Fireware OS. The flaw is triggered when the system processes specially crafted IKEv2 messages. It specifically impacts configurations involving Mobile User VPN with IKEv2 and Branch Office VPN using IKEv2 with a dynamic gateway peer. An unauthenticated remote attacker can exploit this to cause a crash of the VPN service or the entire device, resulting in a denial-of-service (DoS). Patches are available in versions 12.12.1 and 2026.2.1, though some older versions (11.x and 12.5.x) remain unresolved or are End of Life.
Affected products
- WatchGuard Fireware OS 11.10.2 - 11.12.4_Update1, 12.0 - 12.12, 12.5 - 12.5.18, 2025.1 - 2026.2
Timeline
- 2026-07-02: advisory: Initial advisory published by WatchGuard
- 2026-07-03: disclosed: NVD publication date