CVE-2026-19314: Fireware OS Integer Underflow in iked Allows Unauthenticated Denial of Service (DoS)
An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 2026.3.1 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 2026.2.2 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.12.2 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.5.20 - Compensating control
Mitigate the iked integer underflow DoS by restricting VPN/ike-related traffic access (e.g., limit inbound access to VPN/IKE endpoints to only required sources) until systems are upgraded.
Event History
Frequently Asked Questions
Does exploitation require valid VPN credentials or prior access?
No. The issue can be triggered by a remote unauthenticated attacker using specially crafted network traffic.
Which systems should be prioritized for review?
Prioritize WatchGuard Fireware OS deployments where network traffic can reach the iked process or VPN processing functionality, because the reported impact is denial of service in VPN processing.
Is any impact beyond service availability reported?
The provided information reports a denial-of-service condition only. It does not describe confidentiality or integrity impact.