CVE-2026-19317
largeOut-of-Bounds Read DoS in WatchGuard Fireware OS iked VPN Processing
CVE-2026-19317 is an out-of-bounds read (CWE-125) in the iked process of WatchGuard Fireware OS, the daemon that handles IKE-based VPN negotiations. A remote, unauthenticated attacker can trigger it by sending specially crafted network traffic to a Firebox that is processing VPN traffic. The result is a Denial of Service condition in VPN processing: per the CVSS 4.0 score, impact is high on availability only, with no confidentiality or integrity impact. Any organization running WatchGuard Fireware OS with IKE-based VPN (Mobile VPN with IKEv2 or branch office VPN) enabled on an internet-reachable interface is affected; exact affected version ranges are not included in the available data and should be taken from the WatchGuard security advisory. Exploitation is not currently known: there is no public proof of concept, the issue is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.
What to do: Watch for the WatchGuard advisory and upgrade Fireware OS to the fixed release it specifies as soon as it is published; the affected version ranges are not stated in the available data, so do not rely on this notice alone for patch targeting. Until patching, restrict UDP 500 and 4500 on external interfaces to known VPN peer addresses and disable Mobile VPN with IKEv2 or branch office VPNs where they are not required. Audit each Firebox's VPN configuration to confirm whether iked is exposed to the internet.
| WatchGuard Fireware OS (iked process) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
- Weakness
- CWE-125, CWE-191
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.