CVE-2026-86132: Fireware OS Pre-Authentication Integer Underflow in iked Allows Denial of Service
An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with an AES-GCM cipher suite.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 2026.3.2 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 2026.2.3 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.12.3 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.5.21
Event History
Frequently Asked Questions
What must an attacker be able to do to exploit this issue?
An attacker must be able to send a specially crafted encrypted IKEv2 message to the affected iked service. No authentication is required, but the message must have been negotiated with an AES-GCM cipher suite.
What is the expected impact of successful exploitation?
Successful exploitation crashes the IKEv2 daemon process, resulting in a denial of service for that process.