ZeroHour

CVE-2026-19315

large

Unauthenticated Type Confusion RCE in WatchGuard Fireware OS iked

CVSS 4.0
9.3 critical
EPSS
<1%p38
Published
()
Modified
AI analysis

CVE-2026-19315 is a type confusion flaw (CWE-843, with associated out-of-bounds read CWE-125) in the iked process, the IKE daemon that handles IPsec VPN key exchange in WatchGuard Fireware OS. A remote, unauthenticated attacker can trigger the bug by sending specially crafted network traffic to the IKE service, typically reachable on UDP 500/4500. Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity, and availability (CVSS 4.0 base score of 9.3, critical). Any organization running WatchGuard Firebox appliances with Fireware OS, particularly those exposing the IKE/VPN service to the internet, is potentially affected. There is no evidence of in-the-wild exploitation: no public proof-of-concept is known, the issue is not in CISA's KEV catalog, and EPSS puts the 30-day exploitation probability at only 0.5% (38th percentile).

What to do: Identify all WatchGuard Firebox appliances in your estate, determine whether iked/IKE is enabled and reachable from the internet, and apply the patched Fireware OS release specified in WatchGuard's advisory (exact version numbers are not provided in the available data). Until you can patch, restrict inbound IKE (UDP 500/4500) to trusted VPN peers where feasible and monitor the daemon for anomalous activity. Since no public PoC exists yet, prioritize internet-facing VPN endpoints and re-check vendor advisories as details firm up.

Affected
WatchGuard Fireware OS (iked / IKE daemon, running on Firebox appliances)
Estimated exposure
largeon the order of 10,000s–100,000s of internet-exposed Firebox appliances with IKE/VPN enabled (est.) — WatchGuard Fireboxes are widely deployed at SMB and branch-office sites where IKE (UDP 500/4500) is commonly exposed for site-to-site or remote-access VPN, and public internet scans routinely show tens of thousands of reachable WatchGuard…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

Weakness
CWE-125, CWE-763, CWE-843
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.