CVE-2026-78011
largeInteger Underflow DoS in WatchGuard Fireware OS VPN (iked)
CVE-2026-78011 is an integer underflow (CWE-191) in the iked process of WatchGuard Fireware OS, the daemon that handles IKE negotiation for the platform's VPN services, and it can lead to memory corruption such as an out-of-bounds write (CWE-787). A remote, unauthenticated attacker can trigger it by sending specially crafted network traffic to the device's exposed VPN/IKE service, with no credentials or user interaction required. The result is a denial-of-service condition in VPN processing; per the CVSS 4.0 score, availability impact is high while confidentiality and integrity are unaffected. Organizations running WatchGuard Firebox appliances or other devices running Fireware OS with IKE-based VPN (such as Mobile VPN with IKEv2 or branch-office VPN) reachable from untrusted networks are affected. There is currently no known exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a 0.3% probability of exploitation within 30 days.
What to do: Check WatchGuard's security advisory for this CVE to identify affected and fixed Fireware OS releases, and apply the vendor patch, since no version numbers are provided in the available data. In the interim, restrict inbound UDP 500/4500 (IKE) to trusted peers where feasible or disable unused IKE-based VPN services, and monitor Firebox logs for iked process restarts or crashes that would indicate exploitation attempts. If VPN processing suddenly becomes unavailable, restart the affected service or appliance as a temporary recovery measure.
| WatchGuard Fireware OS (iked process, used on Firebox appliances) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
- Weakness
- CWE-191, CWE-787
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.