Junglewise Threat Intelligence

CVE-2026-78009: WatchGuard Fireware OS out-of-bounds read in iked

CVE-2026-78009 · Severity: info · CVSS 8.7 · Published 2026-08-28

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

WatchGuard Fireware OS is the operating system used in WatchGuard firewalls to protect corporate networks and manage VPN connections. An out-of-bounds read vulnerability in the iked (IPsec key daemon) process allows remote attackers to crash the VPN service without authentication, causing denial of service to users relying on VPN access.

Technical details

The vulnerability is an out-of-bounds read in the iked process of WatchGuard Fireware OS, triggered by improper input validation (CWE-20, CWE-125). A remote unauthenticated attacker can send specially crafted network traffic to trigger the out-of-bounds read, causing a denial of service condition in VPN processing. The attack requires no authentication or user interaction and is network-reachable. Patches are available in Fireware OS 2026.3.1, 2026.2.2, 12.12.2, and 12.5.20 for affected platforms.

Affected products

  • WatchGuard Fireware OS versions < 2026.3.1, 2025.0-2026.2.1, 12.0-12.12.1 (Default), and 12.0-12.5.19 (T15/T35)

Timeline

  • 2026-08-27: disclosed
  • 2026-08-28: advisory
  • 2026-09-03: patched: advisory updated with patch availability

References

Related threats