CVE-2026-13368: WatchGuard Firebox Race Condition and Use-After-Free in Mobile VPN with IKEv2 LDAP Authentication
WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 2026.2.1 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.12.1 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.5.19
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13368?
The severity of CVE-2026-13368 is critical with a CVSS score of 9.2.
How do I fix CVE-2026-13368?
To fix CVE-2026-13368, it is recommended to apply the latest patches available for WatchGuard Fireware OS.
What can attackers do with CVE-2026-13368?
Attackers can exploit CVE-2026-13368 to execute arbitrary code in the context of the iked process on vulnerable Fireboxes.
Which software is affected by CVE-2026-13368?
CVE-2026-13368 affects WatchGuard Fireware OS.
What type of vulnerability is CVE-2026-13368?
CVE-2026-13368 is a use-after-free vulnerability that results from a race condition in LDAP authentication for Mobile User VPN with IKEv2.