Junglewise Threat Intelligence

CVE-2026-19316: WatchGuard Fireware OS double-free in iked DoS

CVE-2026-19316 · Severity: info · CVSS 8.7 · Published 2026-08-28

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

WatchGuard Fireware OS is the operating system running on WatchGuard firewalls, which protect corporate networks and VPN access. A double-free vulnerability in the iked (IKE daemon) process allows remote attackers without credentials to crash the VPN service by sending specially crafted network packets, causing a denial of service that disrupts all VPN users' connectivity.

Technical details

A double-free vulnerability (CWE-415) exists in the WatchGuard Fireware OS iked process that processes IKE (Internet Key Exchange) protocol traffic. The vulnerability requires no authentication and is reachable over the network via specially crafted IKE packets. An attacker can trigger the double-free condition to crash the iked process, causing a denial of service to VPN clients and potentially affecting network operations. Patches are available: Fireware OS 2026.3.1, 2026.2.2, 12.12.2, and 12.5.20.

Affected products

  • WatchGuard Fireware OS 2026.3 before 2026.3.1, 2025.0 before 2026.2.2, 12.0 before 12.12.2
  • WatchGuard Firebox T15 12.0 before 12.5.20
  • WatchGuard Firebox T35 12.0 before 12.5.20

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Patches released: Fireware OS 2026.3.1, 2026.2.2, 12.12.2, and 12.5.20

References

Related threats