CVE-2026-18145: WatchGuard Fireware

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending a specially crafted management request.

Affected products

  • WatchGuard Fireware: from 12.0, before 12.5.21 (fixed in 12.5.21); from 12.12, before 12.12.3 (fixed in 12.12.3); from 2025.2, before 2026.2.3 (fixed in 2026.2.3); from 2026.3, before 2026.3.2 (fixed in 2026.3.2)

Published 2026-09-30. Last modified 2026-10-08.