CVE-2026-19318: WatchGuard Fireware OS
Critical severity, CVSS 9.3. EPSS: 0.5% chance of exploitation in the next 30 days.
A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
Affected products
- WatchGuard Fireware OS: from 2025.0, before 2026.2.2 (fixed in 2026.2.2); from 12.0, before 12.12.2 (fixed in 12.12.2); from 12.0, before 12.5.20 (fixed in 12.5.20); from 2026.3, before 2026.3.1 (fixed in 2026.3.1)
Published 2026-08-28. Last modified 2026-09-03.