CVE-2026-19315: Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code Execution
A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 2026.3.1 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 2026.2.2 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.12.2 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.5.20 - Compensating control
Mitigate exposure by blocking or restricting inbound access to the iked service from untrusted networks until the Fireware OS update is applied (remote unauthenticated exploitation via crafted network traffic).
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
A remote, unauthenticated attacker can exploit it by sending specially crafted network traffic to the affected iked process.
What level of access can successful exploitation provide?
Successful exploitation can allow the attacker to execute arbitrary code.