CVE-2026-19318: Fireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Code Execution
Published Aug 27, 2026
·Updated
A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
Affected Software
1 affected component
WatchGuard Fireware OS
Event History
Aug 27, 2026
CVE Published
via MITRE·11:24 PM
Data Sourced
via MITRE·11:24 PM
RemedyDescriptionWeakness
Aug 28, 2026
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A remote, unauthenticated attacker can exploit the vulnerability by sending specially crafted network traffic to the affected iked process.
2
Does exploitation require valid credentials or prior access?
No. The issue is pre-authentication, so the attacker does not need to authenticate before attempting exploitation.
3
What is the potential impact of successful exploitation?
Successful exploitation can allow the attacker to execute arbitrary code on the affected WatchGuard Fireware OS device.