CVE-2026-19316
largeDouble-free DoS in WatchGuard Fireware OS IKE daemon (iked)
CVE-2026-19316 is a double-free memory-corruption flaw (CWE-415, with related CWE-416) in the iked process of WatchGuard Fireware OS, the OS that runs on Firebox firewalls. A remote, unauthenticated attacker can trigger it by sending specially crafted network traffic to the device's IKE/IPsec VPN service, causing iked to free the same memory twice and crash. The result is a denial-of-service condition in VPN processing — IPsec VPN tunnels can go down and repeatedly crash — with no confidentiality or integrity impact per the CVSS 4.0 score of 8.7 (AV:N/PR:N/UI:N, availability only). Any Firebox deployment running Fireware OS with the IKE/IPsec VPN service reachable from untrusted networks is affected; the source data does not specify affected version ranges, and no patched versions are named in the available information. No public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS puts exploitation probability in the next 30 days at just 0.3% (25th percentile), so no exploitation is currently known.
What to do: Watch WatchGuard's security advisory and upgrade Fireware OS to the fixed release it names (fixed versions are not stated in the available data). As interim mitigation, restrict inbound IKE traffic (UDP 500 and 4500) to known VPN peer addresses or disable IPsec VPN if it is unused. Check device logs for iked crashes or VPN tunnel flaps, which would indicate attempted or successful triggering.
| WatchGuard Fireware OS (iked / IKE-IPsec VPN processing) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
- Weakness
- CWE-415, CWE-416
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.