Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-13368: WatchGuard Firebox: Unauthenticated Code Execution via IKEv2 LDAP Auth

CVE-2026-13368 · published 2 months ago
Summary

A vulnerability in WatchGuard Firebox's Mobile User VPN with IKEv2 allows an attacker to run unauthorized code on affected devices. This affects WatchGuard Firebox devices using IKEv2 with an external LDAP server for authentication. To stay secure, update your Firebox devices to the latest version of Fireware OS.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
watchguard fireware os <= 11.12.4+541730
< 2026.2.1
< 12.5.19
< 12.11.9
watchguard fireware >= 2025.1, < 2026.2.1
>= 12.5, < 12.5.19
>= 11.0.0, < 11.12.4
11.12.4
>= 12.0, < 12.12.1
cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*
Original advisory text
WatchGuard Firebox Race Condition and Use-After-Free in Mobile VPN with IKEv2 LDAP Authentication
WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.2 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-416Use After Free
Timeline
Published3 Jul 2026
Updated27 Sep 2026
First seen2 Jul 2026
Sources
CVE-2026-13368 · MITRE
Track software like this
Free during beta