CVE-2026-86133: Fireware OS Pre-Authentication Integer Underflow in iked Allows Remote Denial of Service
An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message, resulting in a denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 2026.3.2 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 2026.2.3 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.12.3 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.5.21
Event History
Frequently Asked Questions
What does an attacker need before they can trigger the denial of service?
The attacker must complete the initial IKEv2 handshake and then send a specially crafted encrypted IKEv2 message to the iked daemon.
What is the operational impact of successful exploitation?
Successful exploitation crashes the iked process, causing a denial of service.