Executive brief
WatchGuard Fireware OS is a widely deployed firewall and VPN gateway that protects networks and secures remote access. A remote attacker can crash the VPN service without authentication by sending specially crafted network packets, disrupting all VPN connections and potentially affecting business continuity for organizations relying on remote access.
Technical details
An integer underflow vulnerability exists in the iked (IKE daemon) process of WatchGuard Fireware OS, allowing remote unauthenticated attackers to trigger a Denial of Service condition. The vulnerability stems from improper handling of integer arithmetic (CWE-191) that can lead to out-of-bounds memory writes (CWE-787). The attack requires only network reachability to the VPN service and no prior authentication; a specially crafted IKE packet will cause the iked process to crash, terminating VPN services. Patches are available: Fireware OS 2026.3.1, 2026.2.2, 12.12.2, and 12.5.20 address the flaw in their respective product lines.
Affected products
- WatchGuard Fireware OS Default (12.0-12.12.1, 2025.0-2026.2.1, 2026.3-2026.3.0); T15/T35 (12.0-12.5.19)
Timeline
- 2026-08-27: disclosed
- 2026-08-28: advisory: Published on NVD
- 2026-08-27: patched: Patches available: Fireware OS 2026.3.1, 2026.2.2, 12.12.2, 12.5.20