CVE-2026-19316: Fireware OS Pre-Authentication Double Free in iked Allows Denial of Service (DoS)
Published Aug 27, 2026
·Updated
A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
Affected Software
1 affected component
WatchGuard Fireware OS
Event History
Aug 27, 2026
CVE Published
via MITRE·11:24 PM
Data Sourced
via MITRE·11:24 PM
RemedyDescriptionWeakness
Aug 28, 2026
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A remote, unauthenticated attacker can exploit it by sending specially crafted network traffic to the affected VPN processing service.
2
What is the impact of successful exploitation?
Successful exploitation can create a denial-of-service condition in the iked process, disrupting VPN processing.