A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
Advisories
No advisories yet.
Fixes
Solution
Fireware OS 2026.2.2, Fireware OS 12.12.2, Fireware OS 12.5.20
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://psirt.watchguard.com/CVE-2026-19318 |
|
History
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. | |
| Title | Fireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Code Execution | |
| First Time appeared |
Watchguard
Watchguard fireware Os |
|
| Weaknesses | CWE-121 CWE-129 CWE-191 |
|
| CPEs | cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Watchguard
Watchguard fireware Os |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WatchGuard
Published:
Updated: 2026-08-27T23:24:32.589Z
Reserved: 2026-08-07T20:06:03.527Z
Link: CVE-2026-19318
No data.
Status : Received
Published: 2026-08-28T02:16:21.070
Modified: 2026-08-28T02:16:21.070
Link: CVE-2026-19318
No data.
OpenCVE Enrichment
No data.