Executive brief
WatchGuard Fireware OS is a firewall operating system used to protect corporate networks and provide VPN connectivity. An out-of-bounds read vulnerability in the VPN processing component (iked) allows an unauthenticated attacker to crash the firewall's VPN service by sending specially crafted network packets, potentially disrupting remote employee access and business continuity.
Technical details
The vulnerability is an out-of-bounds read (CWE-125) combined with an integer underflow (CWE-191) in the iked process of WatchGuard Fireware OS. The flaw can be triggered pre-authentication via specially crafted network traffic targeting VPN processing. An unauthenticated remote attacker on the network can exploit this to cause a Denial of Service by crashing or hanging the iked process, disabling VPN functionality. Patches are available in Fireware OS versions 2026.3.1, 2026.2.2, 12.12.2, and 12.5.20 for affected product lines.
Affected products
- WatchGuard Fireware OS 2026.3 before 2026.3.1, 2025.0 through before 2026.2.2, 12.0 before 12.12.2 (Default); 12.0 before 12.5.20 (T15/T35)
Timeline
- 2026-08-27: disclosed
- 2026-08-28: advisory
- 2026-09-03: other: Advisory updated