Junglewise Threat Intelligence

CVE-2026-78010: WatchGuard Fireware OS stack-based buffer overflow in iked

CVE-2026-78010 · Severity: info · CVSS 8.7 · Published 2026-08-28

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

WatchGuard Fireware OS is the operating system that runs on WatchGuard network firewalls, which protect corporate networks by filtering traffic and managing VPN connections. A vulnerability in the VPN processing component allows an attacker outside the network to remotely crash the firewall's VPN service without authentication, causing a denial of service and potentially disrupting remote employee access.

Technical details

A stack-based buffer overflow vulnerability exists in the iked (IKE daemon) process of WatchGuard Fireware OS, triggered by specially crafted network traffic during VPN processing. The vulnerability stems from improper validation of input quantity (CWE-121, CWE-787, CWE-1284) and allows an unauthenticated remote attacker to send malicious packets over the network to cause a denial of service condition. No authentication is required and the attack vector is network-based. Patches are available in Fireware OS versions 2026.3.1, 2026.2.2, 12.12.2, and 12.5.20 (depending on deployment series). WatchGuard reports no known exploitation in the wild as of the advisory date.

Affected products

  • WatchGuard Fireware OS Default: <2026.3.1 (2026.3.x series), <2026.2.2 (2026.2.x series), <12.12.2 (12.x series); T15/T35: <12.5.20

Timeline

  • 2026-08-27: disclosed
  • 2026-08-28: advisory
  • 2026-09-03: patched: Multiple patch versions released

References

Related threats