ZeroHour

CVE-2026-19313

large

Heap overflow in WatchGuard Fireware OS IKE daemon enables unauthenticated RCE

CVSS 4.0
9.3 critical
EPSS
<1%p39
Published
()
Modified
AI analysis

CVE-2026-19313 is a heap-based buffer overflow (CWE-122) involving an integer overflow component (CWE-190/CWE-680) in the iked (Internet Key Exchange daemon) process of WatchGuard Fireware OS. A remote, unauthenticated attacker can trigger the flaw by sending specially crafted network traffic to the IKE/IPsec VPN service, which on perimeter firewalls is commonly reachable on UDP ports 500 and 4500. Successful exploitation yields arbitrary code execution in the context of the iked process, which on an edge firewall typically means full compromise of the appliance and a foothold into the protected network. Affected organizations are those running WatchGuard fireboxes/appliances on Fireware OS with IKE/IPsec VPN enabled or exposed. As of now there is no public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates only a 0.5% chance of exploitation in the next 30 days, but pre-auth RCE on internet-facing security appliances is a high-value target and should be treated as urgent.

What to do: Upgrade Fireware OS to the patched release identified in WatchGuard's security advisory (no specific fixed version is listed in this data, so consult the vendor bulletin). Until patching is complete, restrict inbound IKE traffic (UDP 500 and 4500) to trusted VPN peer addresses where possible and monitor for iked crashes or unexpected processes on the appliance.

Affected
WatchGuard Fireware OS (iked / IKE daemon)
Estimated exposure
largetens of thousands of internet-exposed WatchGuard Firebox appliances (subset of WatchGuard's large installed base with IKE/IPsec reachable) — WatchGuard Firebox appliances have a large installed base among SMB and mid-market networks, and internet-wide scan data of UDP 500/4500 (IKE) suggests tens of thousands of exposed devices, with only the IKE-exposed subset vulnerable.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

Weakness
CWE-122, CWE-190, CWE-680
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.