CVE-2026-19315: Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code Execution
Published Aug 27, 2026
·Updated
A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
Affected Software
1 affected component
WatchGuard Fireware OS
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Fireware OS (iked process)to a version that resolves this vulnerability.Fixed in 2026.2.2 - Upgrade
Upgrade
WatchGuard Fireware OS (iked process)to a version that resolves this vulnerability.Fixed in 12.12.2 - Upgrade
Upgrade
WatchGuard Fireware OS (iked process)to a version that resolves this vulnerability.Fixed in 12.5.20
Event History
Aug 27, 2026
CVE Published
via MITRE·11:24 PM
Data Sourced
via MITRE·11:24 PM
RemedyDescriptionWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
A remote, unauthenticated attacker can exploit it by sending specially crafted network traffic to the affected iked process.
2
What level of access can successful exploitation provide?
Successful exploitation can allow the attacker to execute arbitrary code.