Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-19318: WatchGuard Fireware OS lets remote attacker run code

CVE-2026-19318 · published 1 month ago
Summary

The iked component in WatchGuard Fireware OS can be tricked by specially crafted network traffic, allowing someone on the internet to run their own programs on the device. This could let attackers take control or disrupt services. Apply the latest security update from WatchGuard as soon as possible to close the gap.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
watchguard fireware os < 2026.2.2
< 12.5.20
Original advisory text
Fireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Code Execution
A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-121Stack-based Buffer Overflow
CWE-129Improper Validation of Array Index
CWE-191Integer Underflow (Wrap or Wraparound)
Timeline
Published28 Aug 2026
Updated27 Sep 2026
First seen29 Aug 2026
Sources
CVE-2026-19318 · MITRE
Track software like this
Free during beta