CVE-2026-19313: Fireware OS Pre-Authentication Heap Buffer Overflow in iked Allows Remote Code Execution
An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Fireware OS (iked)to a version that resolves this vulnerability.Fixed in 2026.2.2 - Upgrade
Upgrade
WatchGuard Fireware OS (iked)to a version that resolves this vulnerability.Fixed in 12.12.2 - Upgrade
Upgrade
WatchGuard Fireware OS (iked)to a version that resolves this vulnerability.Fixed in 12.5.20
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote, unauthenticated attacker can exploit the vulnerability by sending specially crafted network traffic to the affected iked process.
What level of access does successful exploitation provide?
Successful exploitation can allow an attacker to execute arbitrary code on the affected WatchGuard Fireware OS system.