Junglewise Threat Intelligence

CVE-2026-81851: WatchGuard Fireware OS heap buffer overflow in iked

CVE-2026-81851 · Severity: info · CVSS 6.9 · Published 2026-08-28

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

Fireware OS is an operating system used on WatchGuard firewalls to protect network traffic. An authenticated administrator with configuration privileges can trigger a heap buffer overflow in the IKE daemon (iked), causing it to crash and disrupting VPN connectivity. This denial-of-service vulnerability requires administrator access and a specially crafted configuration to exploit.

Technical details

A heap-based buffer overflow vulnerability exists in Fireware OS's iked (IKE daemon) process when processing specially crafted configuration inputs. The vulnerability stems from improper validation of the quantity and format of configuration parameters (CWE-122, CWE-1284). An authenticated administrator can save a malicious configuration that triggers the overflow, crashing the iked daemon and causing denial of service. Affected versions include Fireware OS Default versions 2025.0 through 2026.2.0, T15/T35 versions 12.0 through 12.5.17, and EUCC versions 12.0 through 12.11.8. Patches are available in Fireware OS 2026.2.1, 12.12.1, 12.11.9, and 12.5.18. WatchGuard reports no known exploitation in the wild.

Affected products

  • WatchGuard Fireware OS Default 2025.0 - 2026.2.0, T15/T35 12.0 - 12.5.17, EUCC 12.0 - 12.11.8

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Fireware OS 2026.2.1, 12.12.1, 12.11.9, 12.5.18

References

Related threats