CVE-2026-19318: Fireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Code Execution
A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Fireware OS (iked process)to a version that resolves this vulnerability.Fixed in 2026.2.2 - Upgrade
Upgrade
WatchGuard Fireware OS (iked process)to a version that resolves this vulnerability.Fixed in 12.12.2 - Upgrade
Upgrade
WatchGuard Fireware OS (iked process)to a version that resolves this vulnerability.Fixed in 12.5.20
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote, unauthenticated attacker can exploit the vulnerability by sending specially crafted network traffic to the affected iked process.
Does exploitation require valid credentials or prior access?
No. The issue is pre-authentication, so the attacker does not need to authenticate before attempting exploitation.
What is the potential impact of successful exploitation?
Successful exploitation can allow the attacker to execute arbitrary code on the affected WatchGuard Fireware OS device.