CVE-2026-78010: Fireware OS Stack-Based Buffer Overflow in iked Allows Unauthenticated Denial of Service
A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process iallows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Fireware OS ikedto a version that resolves this vulnerability.Fixed in 2026.2.2 - Upgrade
Upgrade
WatchGuard Fireware OS ikedto a version that resolves this vulnerability.Fixed in 12.12.2 - Upgrade
Upgrade
WatchGuard Fireware OS ikedto a version that resolves this vulnerability.Fixed in 12.5.20
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments running WatchGuard Fireware OS with VPN processing exposed to network traffic are relevant, because the affected iked process handles VPN-related traffic. The provided information does not identify specific versions or configurations.
What does an attacker need to exploit it?
An attacker can be remote and unauthenticated. Exploitation requires sending specially crafted network traffic to trigger the stack-based buffer overflow in iked.
What is the expected impact?
The stated impact is a denial-of-service condition in VPN processing. The provided information does not claim code execution, authentication bypass, or data exposure.