Executive brief
WatchGuard Fireware OS is an operating system for network firewalls and VPN gateways that protects corporate network perimeters. An integer underflow vulnerability in the VPN processing component (iked daemon) allows unauthenticated remote attackers to crash the firewall and disrupt VPN connectivity by sending specially crafted network packets, causing a denial of service condition.
Technical details
An integer underflow vulnerability (CWE-191) exists in the WatchGuard Fireware OS iked process, which handles IPsec VPN negotiations. The flaw results in an out-of-bounds write (CWE-787) when processing specially crafted network traffic. An unauthenticated remote attacker can exploit this vulnerability over the network without requiring authentication or user interaction by sending malicious packets to the VPN endpoint, causing the iked daemon to crash and disrupting VPN services. WatchGuard has released patches in Fireware OS versions 2026.3.1, 2026.2.2, 12.12.2, and 12.5.20; no exploitation in the wild has been reported.
Affected products
- WatchGuard Fireware OS 2026.3 < 2026.3.1, 2025.0–2026.2.1, 12.0–12.12.1 (T15/T35: 12.0–12.5.19)
Timeline
- 2026-08-27: disclosed
- 2026-08-27: patched: Patches released in Fireware OS 2026.3.1, 2026.2.2, 12.12.2, and 12.5.20