CVE-2026-19313: WatchGuard Fireware OS

Critical severity, CVSS 9.3. EPSS: 0.5% chance of exploitation in the next 30 days.

An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

Affected products

  • WatchGuard Fireware OS: from 2025.0, before 2026.2.2 (fixed in 2026.2.2); from 12.0, before 12.12.2 (fixed in 12.12.2); from 12.0, before 12.5.20 (fixed in 12.5.20); from 2026.3, before 2026.3.1 (fixed in 2026.3.1)

Published 2026-08-28. Last modified 2026-09-03.