ZeroHour

CVE-2026-19318

large

Unauthenticated RCE in WatchGuard Fireware OS IKE daemon (iked)

CVSS 4.0
9.3 critical
EPSS
<1%p39
Published
()
Modified
AI analysis

CVE-2026-19318 is a stack-based buffer overflow (with related integer-underflow and array-index validation weaknesses, CWE-191/CWE-129) in the iked process of WatchGuard's Fireware OS, the daemon that handles Internet Key Exchange for IPSec VPNs. A remote, unauthenticated attacker can trigger it by sending specially crafted network traffic that the iked process parses, which is typically reachable wherever a Firebox exposes IKE/IPSec VPN services on its external interface. Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity and availability of the appliance per the CVSS 4.0 vector, meaning the security appliance itself can be fully compromised as a foothold. Any organization running WatchGuard Firebox appliances on a vulnerable Fireware OS release with the IKE daemon reachable is affected; the specific vulnerable version ranges are in the vendor's advisory and are not enumerated in the source data provided. Exploitation has not been reported yet: the flaw carries a modest 0.5% EPSS probability of exploitation within 30 days (39th percentile), is not in CISA's KEV catalog, and no public proof-of-concept is known.

What to do: Upgrade Firebox appliances to the patched Fireware OS release identified in WatchGuard's advisory for CVE-2026-19318. Until patched, restrict IKE (UDP 500 and 4500) on external interfaces to trusted peer addresses, or disable IPSec VPN/iked where it is not in use, and check which Fireboxes have IKE services exposed. Prioritize appliances that terminate site-to-site or remote-access IPSec VPNs, since those are the most likely to have iked reachable by unauthenticated attackers.

Affected
WatchGuard Fireware OS (running on Firebox appliances)
Estimated exposure
large≈10k–100k internet-exposed Firebox appliances — WatchGuard's publicly stated shipped appliance base exceeds one million Fireboxes, and public internet scans of UDP 500/4500 (IKE) typically surface tens of thousands of reachable Fireboxes, so the subset running a vulnerable Fireware OS…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

Weakness
CWE-121, CWE-129, CWE-191
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.