An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
Advisories
No advisories yet.
Fixes
Solution
Fireware OS 2026.2.2, Fireware OS 12.12.2, Fireware OS 12.5.20
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://psirt.watchguard.com/CVE-2026-78009 |
|
History
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Title | Fireware OS Out-of-Bounds Read in iked Allows Unauthenticated Denial of Service (DoS) | |
| First Time appeared |
Watchguard
Watchguard fireware Os |
|
| Weaknesses | CWE-125 CWE-20 |
|
| CPEs | cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Watchguard
Watchguard fireware Os |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WatchGuard
Published:
Updated: 2026-08-27T23:24:32.671Z
Reserved: 2026-08-21T21:46:42.399Z
Link: CVE-2026-78009
No data.
Status : Received
Published: 2026-08-28T02:16:22.293
Modified: 2026-08-28T02:16:22.293
Link: CVE-2026-78009
No data.
OpenCVE Enrichment
Updated: 2026-08-28T07:30:07Z