CVE-2026-13383: WatchGuard Firebox ikestubd Out of Bounds Write Vulnerability
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the Fireware OS Management Web UI to trusted users/sources only (e.g., via network ACL/firewall allow-listing) until the system is patched, since exploitation requires an authenticated privileged user via crafted requests to the Management Web UI.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13383?
The severity of CVE-2026-13383 is rated high with a CVSS score of 8.6.
How do I fix CVE-2026-13383?
To fix CVE-2026-13383, update your WatchGuard Fireware OS to version 12.13 or later.
What type of vulnerability is CVE-2026-13383?
CVE-2026-13383 is an Out-of-Bounds Write vulnerability.
Who is affected by CVE-2026-13383?
CVE-2026-13383 affects authenticated privileged users using WatchGuard Fireware OS versions 12.1 to 12.12 and 2025.1.
What can an attacker do with CVE-2026-13383?
An attacker exploiting CVE-2026-13383 can execute arbitrary code on the affected system via specially crafted requests.