Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

WatchGuard Patches Critical Vulnerabilities

Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely.

Vulnerability

WatchGuard has released patches for over two dozen vulnerabilities, including five critical-severity flaws leading to remote code execution (RCE) and account takeover.

Three of the critical bugs impact the iked process of Fireware OS, the core Internet Key Exchange (IKE) daemon that handles cryptographic key establishment and manages IPsec VPN negotiations over the IKEv1 and IKEv2 protocols.

Exploitable without authentication, the three security defects are a heap buffer overflow (CVE-2026-19313), a stack-based buffer overflow (CVE-2026-19318), and a type confusion (CVE-2026-19315).

Attackers could send specially crafted network traffic to trigger each of these vulnerabilities and achieve RCE, WatchGuard says.

WatchGuard also patched a critical stack-based buffer overflow bug (CVE-2026-13086) in the Endpoint Protection Manager (epm) service that is used by the deprecated Mobile Security feature in Fireware OS, which could lead to RCE.

Additionally, the company fixed CVE-2026-78174 in WatchGuard Dimension, which could allow low-privileged administrators to extract a super admin’s session ID and CSRF tokens and take over their account.

Advertisement. Scroll to continue reading.

All five security defects have a CVSS score of 9.3. Fixes for them were included in Fireware OS versions 2026.2.2, 12.12.2, and 12.5.20, and Dimension version 2.3.1.

The updates also resolve seven high-severity Fireware OS vulnerabilities that could lead to denial-of-service (DoS), including six impacting the iked process, and five high-severity Dimension bugs leading to arbitrary command execution, tampering with the global administrator’s passphrase, and DoS.

Patches were also rolled out for 11 medium-severity vulnerabilities, including one in Fireware OS’s iked process and 10 in Dimension.

WatchGuard says it is not aware of any of these security defects being exploited in the wild. Additional information can be found on the company’s security advisories page.

Related: PaperCut Exploitation Escalates to Active Intrusions

Related: Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit

Related: ServiceNow Patches 3 Critical Code Injection Vulnerabilities

Related: Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Social engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.

Naveen Bhateja has been appointed Chief People Officer at HackerOne.

The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.