CVE-2026-19317: Fireware OS Pre-Authentication Out-of-Bounds Read in iked Allows Denial of Service (DoS)
Published Aug 27, 2026
·Updated
An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
Affected Software
1 affected component
WatchGuard Fireware OS
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Fireware OS ikedto a version that resolves this vulnerability.Fixed in 2026.2.2 - Upgrade
Upgrade
WatchGuard Fireware OS ikedto a version that resolves this vulnerability.Fixed in 12.12.2 - Upgrade
Upgrade
WatchGuard Fireware OS ikedto a version that resolves this vulnerability.Fixed in 12.5.20
Event History
Aug 27, 2026
CVE Published
via MITRE·11:24 PM
Data Sourced
via MITRE·11:24 PM
RemedyDescriptionWeakness
Frequently Asked Questions
1
What underlying weakness is associated with this issue?
The vulnerability is classified as CWE-191, Integer Underflow.