CVE-2026-19316: WatchGuard Fireware OS
High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.
A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
Affected products
- WatchGuard Fireware OS: from 2025.0, before 2026.2.2 (fixed in 2026.2.2); from 12.0, before 12.12.2 (fixed in 12.12.2); from 2026.3, before 2026.3.1 (fixed in 2026.3.1); from 12.0, before 12.5.20 (fixed in 12.5.20)
Published 2026-08-28. Last modified 2026-09-03.