Executive brief
WatchGuard Fireware OS is the operating system used in WatchGuard firewalls to protect networks and manage security policies. A type confusion vulnerability in the iked (IKE daemon) component allows unauthenticated attackers on the network to execute arbitrary code by sending specially crafted packets, potentially giving attackers complete control over the firewall and access to protected network traffic.
Technical details
A type confusion vulnerability (CWE-843) exists in the iked process of WatchGuard Fireware OS, enabling remote code execution without authentication. The vulnerability stems from improper type handling in the IKE daemon, which processes network traffic related to IPsec VPN negotiations. An unauthenticated remote attacker can exploit this by sending specially crafted network packets to trigger an out-of-bounds read (CWE-125) or invalid pointer dereference (CWE-763), leading to arbitrary code execution with firewall privileges. The attack vector is network-based with no authentication required. Patches are available in Fireware OS versions 2026.3.1, 2026.2.2, 12.12.2, and 12.5.20.
Affected products
- WatchGuard Fireware OS 12.0 before 12.12.2, 12.5.x before 12.5.20, 2025.0 before 2026.2.2, 2026.3 before 2026.3.1
Timeline
- 2026-08-27: disclosed
- 2026-08-28: advisory: CVE-2026-19315 published on NVD
- 2026-09-03: patched: Patches released: Fireware OS 2026.3.1, 2026.2.2, 12.12.2, 12.5.20