ZeroHour

CVE-2026-19316

large

Double-free DoS in WatchGuard Fireware OS IKE daemon (iked)

CVSS 4.0
8.7 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-19316 is a double-free memory-corruption flaw (CWE-415, with related CWE-416) in the iked process of WatchGuard Fireware OS, the OS that runs on Firebox firewalls. A remote, unauthenticated attacker can trigger it by sending specially crafted network traffic to the device's IKE/IPsec VPN service, causing iked to free the same memory twice and crash. The result is a denial-of-service condition in VPN processing — IPsec VPN tunnels can go down and repeatedly crash — with no confidentiality or integrity impact per the CVSS 4.0 score of 8.7 (AV:N/PR:N/UI:N, availability only). Any Firebox deployment running Fireware OS with the IKE/IPsec VPN service reachable from untrusted networks is affected; the source data does not specify affected version ranges, and no patched versions are named in the available information. No public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS puts exploitation probability in the next 30 days at just 0.3% (25th percentile), so no exploitation is currently known.

What to do: Watch WatchGuard's security advisory and upgrade Fireware OS to the fixed release it names (fixed versions are not stated in the available data). As interim mitigation, restrict inbound IKE traffic (UDP 500 and 4500) to known VPN peer addresses or disable IPsec VPN if it is unused. Check device logs for iked crashes or VPN tunnel flaps, which would indicate attempted or successful triggering.

Affected
WatchGuard Fireware OS (iked / IKE-IPsec VPN processing)
Estimated exposure
largetens of thousands to ~100,000 internet-exposed Firebox appliances are plausibly affected; only the subset with IKE (UDP 500/4500) reachable from the internet… — Public internet-wide scans (Shodan/Censys) index on the order of tens of thousands of WatchGuard appliances, and WatchGuard's large SMB/MSP installed base suggests many more total Fireboxes, but exploitability is limited to devices…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.

Weakness
CWE-415, CWE-416
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.