ZDI-26-750: WatchGuard FireWare OS spamd statushdlr Stack-based Buffer Overflow Remote Code Execution Vulnerability
Authenticated stack buffer overflow in WatchGuard Fireware OS spamd allows remote code execution (CVE-2026-18145).
ZDI-26-750 describes a stack-based buffer overflow in the spamd statushdlr component of WatchGuard Fireware OS. An authenticated remote attacker can exploit it to execute arbitrary code on affected installations. The Zero Day Initiative assigned CVE-2026-18145 and a CVSS score of 7.2. The advisory does not say the flaw is being exploited.
- Stack-based buffer overflow in Fireware OS spamd statushdlr
- Authenticated remote attackers can execute arbitrary code
- CVE-2026-18145 received a ZDI CVSS rating of 7.2
- Advisory does not report exploitation in the wild
Vulnerabilities mentionedAll →
- CVE-2026-181458.6—Stack buffer overflow in WatchGuard Fireware spamBlockerpublished · WatchGuard Fireware OS (spamBlocker / spamd)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-18145 | Stack buffer overflow in WatchGuard Fireware spamBlocker CVE-2026-18145 is a stack-based buffer overflow (CWE-121) in the spamBlocker (spamd) service of WatchGuard Fireware OS. An attacker who is already authenticated with administrator privileges can trigger it by sending a specially crafted management request over the network. Successful exploitation can crash spamd or, in the worst case, run arbitrary code with the service’s privileges, with high impact to confidentiality, integrity, and availability of the device (CVSS 4.0 8.6). It affects WatchGuard Fireware OS installations where spamBlocker is present; the advisory does not list specific version ranges. It is not in CISA’s Known Exploited Vulnerabilities catalog, and no public proof-of-concept is known. |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-18145.
This source does not provide full text. Read it at zerodayinitiative.com.