WatchGuard has released patches for over two dozen vulnerabilities, including five critical-severity flaws leading to remote code execution (RCE) and account takeover.
Three of the critical bugs impact the iked process of Fireware OS, the core Internet Key Exchange (IKE) daemon that handles cryptographic key establishment and manages IPsec VPN negotiations over the IKEv1 and IKEv2 protocols.
Exploitable without authentication, the three security defects are a heap buffer overflow (CVE-2026-19313), a stack-based buffer overflow (CVE-2026-19318), and a type confusion (CVE-2026-19315).
Attackers could send specially crafted network traffic to trigger each of these vulnerabilities and achieve RCE, WatchGuard says.
WatchGuard also patched a critical stack-based buffer overflow bug (CVE-2026-13086) in the Endpoint Protection Manager (epm) service that is used by the deprecated Mobile Security feature in Fireware OS, which could lead to RCE.
Additionally, the company fixed CVE-2026-78174 in WatchGuard Dimension, which could allow low-privileged administrators to extract a super admin’s session ID and CSRF tokens and take over their account.
All five security defects have a CVSS score of 9.3. Fixes for them were included in Fireware OS versions 2026.2.2, 12.12.2, and 12.5.20, and Dimension version 2.3.1.
The updates also resolve seven high-severity Fireware OS vulnerabilities that could lead to denial-of-service (DoS), including six impacting the iked process, and five high-severity Dimension bugs leading to arbitrary command execution, tampering with the global administrator’s passphrase, and DoS.
Patches were also rolled out for 11 medium-severity vulnerabilities, including one in Fireware OS’s iked process and 10 in Dimension.
WatchGuard says it is not aware of any of these security defects being exploited in the wild. Additional information can be found on the company’s security advisories page.
Related: PaperCut Exploitation Escalates to Active Intrusions
Related: Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit
Related: ServiceNow Patches 3 Critical Code Injection Vulnerabilities
Related: Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs
