AI analysis
CVE-2026-18145 is a stack-based buffer overflow (CWE-121) in the spamBlocker (spamd) service of WatchGuard Fireware OS. An attacker who is already authenticated with administrator privileges can trigger it by sending a specially crafted management request over the network. Successful exploitation can crash spamd or, in the worst case, run arbitrary code with the service’s privileges, with high impact to confidentiality, integrity, and availability of the device (CVSS 4.0 8.6). It affects WatchGuard Fireware OS installations where spamBlocker is present; the advisory does not list specific version ranges. It is not in CISA’s Known Exploited Vulnerabilities catalog, and no public proof-of-concept is known.
What to do: Install the WatchGuard Fireware OS security update that addresses CVE-2026-18145 as soon as it is available for your release; the advisory data does not name a fixed version. Until then, restrict Fireware management access to trusted admin networks, limit who holds administrator credentials, and alert on unexpected spamBlocker (spamd) crashes.
Affected
| WatchGuard Fireware OS (spamBlocker / spamd) | — |
Estimated exposure
largetens to low hundreds of thousands of Firebox/Fireware deployments (vulnerable subset unknown) — WatchGuard Firebox appliances running Fireware OS are a common SMB/branch firewall, with a global install base plausibly in the tens to low hundreds of thousands; no version range or public scan count is in the data, and the bug needs an…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.