CVE-2026-78009
largeUnauthenticated DoS via out-of-bounds read in WatchGuard Fireware OS iked
CVE-2026-78009 is an out-of-bounds read (CWE-125, with improper input validation per CWE-20) in the iked IKE/VPN keying daemon of WatchGuard's Fireware OS. A remote, unauthenticated attacker can trigger it by sending specially crafted network traffic to a device's IKE/VPN processing, with no credentials or user interaction required. The attacker gains a Denial of Service condition in VPN processing (CVSS 4.0 base 8.7, High), meaning VPN services can be disrupted, though the description indicates no code execution or data compromise. Any WatchGuard appliance running a vulnerable Fireware OS release with the iked service reachable (typically on an external interface where IKEv2/VPN is enabled) is affected; the data provided does not include specific affected version ranges, so consult WatchGuard's advisory. Exploitation is not currently observed: the flaw is not in CISA KEV, carries a modest 0.3% EPSS (25th percentile), and no public proof-of-concept is known.
What to do: Upgrade Fireware OS to the fixed release identified in WatchGuard's security advisory for CVE-2026-78009 (version ranges are not included in the available data). Until patched, restrict IKE reachability (UDP 500/4500) on external interfaces to trusted peer addresses, or disable unused IKEv2/mobile VPN services. Administrators should verify whether VPN endpoints are exposed on untrusted interfaces and monitor WatchGuard's advisory for updated affected/fixed version details.
| WatchGuard Fireware OS (iked IKE/VPN daemon, running on Firebox appliances) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
- Weakness
- CWE-20, CWE-125
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.