CVE-2026-19313
largeHeap overflow in WatchGuard Fireware OS IKE daemon enables unauthenticated RCE
CVE-2026-19313 is a heap-based buffer overflow (CWE-122) involving an integer overflow component (CWE-190/CWE-680) in the iked (Internet Key Exchange daemon) process of WatchGuard Fireware OS. A remote, unauthenticated attacker can trigger the flaw by sending specially crafted network traffic to the IKE/IPsec VPN service, which on perimeter firewalls is commonly reachable on UDP ports 500 and 4500. Successful exploitation yields arbitrary code execution in the context of the iked process, which on an edge firewall typically means full compromise of the appliance and a foothold into the protected network. Affected organizations are those running WatchGuard fireboxes/appliances on Fireware OS with IKE/IPsec VPN enabled or exposed. As of now there is no public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates only a 0.5% chance of exploitation in the next 30 days, but pre-auth RCE on internet-facing security appliances is a high-value target and should be treated as urgent.
What to do: Upgrade Fireware OS to the patched release identified in WatchGuard's security advisory (no specific fixed version is listed in this data, so consult the vendor bulletin). Until patching is complete, restrict inbound IKE traffic (UDP 500 and 4500) to trusted VPN peer addresses where possible and monitor for iked crashes or unexpected processes on the appliance.
| WatchGuard Fireware OS (iked / IKE daemon) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
- Weakness
- CWE-122, CWE-190, CWE-680
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.