CVE-2026-19315: WatchGuard Fireware OS
Critical severity, CVSS 9.3. EPSS: 0.5% chance of exploitation in the next 30 days.
A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
Affected products
- WatchGuard Fireware OS: from 2025.0, before 2026.2.2 (fixed in 2026.2.2); from 12.0, before 12.12.2 (fixed in 12.12.2); from 2026.3, before 2026.3.1 (fixed in 2026.3.1); from 12.0, before 12.5.20 (fixed in 12.5.20)
Published 2026-08-28. Last modified 2026-09-03.