CVE-2026-78009: Fireware OS Out-of-Bounds Read in iked Allows Unauthenticated Denial of Service (DoS)
An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Fireware OS ikedto a version that resolves this vulnerability.Fixed in 2026.2.2 - Upgrade
Upgrade
WatchGuard Fireware OS ikedto a version that resolves this vulnerability.Fixed in 12.12.2 - Upgrade
Upgrade
WatchGuard Fireware OS ikedto a version that resolves this vulnerability.Fixed in 12.5.20
Event History
Frequently Asked Questions
Who is exposed to this issue?
WatchGuard Fireware OS systems with VPN processing reachable by a remote attacker are exposed. The attacker does not need to authenticate.
What does an attacker need to do to exploit it?
The attacker needs to send specially crafted network traffic to trigger an out-of-bounds read in the iked process. Successful exploitation can cause a denial-of-service condition affecting VPN processing.