Junglewise Threat Intelligence

CVE-2026-13368: WatchGuard Fireware OS use-after-free in Mobile VPN IKEv2 LDAP auth

CVE-2026-13368 · Severity: info · CVSS 9.2 · Published 2026-07-03

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

WatchGuard Fireware OS, the software powering Firebox security appliances, is vulnerable to a critical flaw in its Mobile VPN component. If the VPN is configured to use an external LDAP server for user logins, a remote attacker can exploit a timing issue to take control of the device. This could lead to a complete compromise of the firewall, allowing unauthorized access to the internal network or the theft of sensitive data.

Technical details

A race condition exists within the 'iked' process of WatchGuard Fireware OS when handling LDAP authentication for Mobile VPN with IKEv2. This timing flaw leads to a use-after-free (UAF) condition. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted authentication requests to a Firebox configured with an external LDAP server. Successful exploitation allows for arbitrary code execution in the context of the iked process. Patches are available for versions 12.x and 2025.x, while version 11.x has reached End of Life.

Affected products

  • WatchGuard Fireware OS 11.0 to 11.12.4_Update1, 12.0 to 12.12, 12.5 to 12.5.18, 2025.1 to 2026.2

Timeline

  • 2026-07-02: advisory
  • 2026-07-02: patched

References

Related threats