ZeroHour

CVE-2026-78009

large

Unauthenticated DoS via out-of-bounds read in WatchGuard Fireware OS iked

CVSS 4.0
8.7 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-78009 is an out-of-bounds read (CWE-125, with improper input validation per CWE-20) in the iked IKE/VPN keying daemon of WatchGuard's Fireware OS. A remote, unauthenticated attacker can trigger it by sending specially crafted network traffic to a device's IKE/VPN processing, with no credentials or user interaction required. The attacker gains a Denial of Service condition in VPN processing (CVSS 4.0 base 8.7, High), meaning VPN services can be disrupted, though the description indicates no code execution or data compromise. Any WatchGuard appliance running a vulnerable Fireware OS release with the iked service reachable (typically on an external interface where IKEv2/VPN is enabled) is affected; the data provided does not include specific affected version ranges, so consult WatchGuard's advisory. Exploitation is not currently observed: the flaw is not in CISA KEV, carries a modest 0.3% EPSS (25th percentile), and no public proof-of-concept is known.

What to do: Upgrade Fireware OS to the fixed release identified in WatchGuard's security advisory for CVE-2026-78009 (version ranges are not included in the available data). Until patched, restrict IKE reachability (UDP 500/4500) on external interfaces to trusted peer addresses, or disable unused IKEv2/mobile VPN services. Administrators should verify whether VPN endpoints are exposed on untrusted interfaces and monitor WatchGuard's advisory for updated affected/fixed version details.

Affected
WatchGuard Fireware OS (iked IKE/VPN daemon, running on Firebox appliances)
Estimated exposure
large≈ tens of thousands (10k–100k) of internet-reachable Firebox appliances with IKE/VPN exposed — WatchGuard Fireboxes are widely deployed at SMB and branch sites through MSP channel partners, and public internet scans have long shown tens of thousands of exposed Firebox VPN/management endpoints; only units with IKE processing…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.

Weakness
CWE-20, CWE-125
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.