Junglewise Threat Intelligence

CVE-2026-19313: WatchGuard Fireware OS heap overflow in iked

CVE-2026-19313 · Severity: info · CVSS 9.3 · Published 2026-08-28

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

WatchGuard Fireware OS is a firewall operating system that manages network security for organizations. A heap buffer overflow vulnerability in the iked (IPsec key exchange daemon) component allows an attacker on the network to send crafted traffic and remotely execute arbitrary code without authentication, potentially compromising the firewall and all traffic flowing through it.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in the WatchGuard Fireware OS iked process, triggered by specially crafted network traffic. The vulnerability is exacerbated by integer overflow issues (CWE-190, CWE-680) that can convert an integer overflow into a buffer overflow. The attack is unauthenticated and network-accessible, requiring only the ability to send malicious packets to the device. A successful exploit results in remote code execution with the privileges of the iked process. Patches are available in Fireware OS versions 2026.3.1, 2026.2.2, 12.12.2, and 12.5.20.

Affected products

  • WatchGuard Fireware OS 2025.0 through 2026.2.1, 12.0 through 12.12.1 (Default); 2026.3 through 2026.3.0, 12.0 through 12.5.19 (T15/T35)

Timeline

  • 2026-08-27: disclosed
  • 2026-08-28: patched: Patches released as Fireware OS 2026.3.1, 2026.2.2, 12.12.2, 12.5.20

References

Related threats