Vulnerabilities

WatchGuard Patches Critical Vulnerabilities

Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely.

Vulnerability

WatchGuard has released patches for over two dozen vulnerabilities, including five critical-severity flaws leading to remote code execution (RCE) and account takeover.

Three of the critical bugs impact the iked process of Fireware OS, the core Internet Key Exchange (IKE) daemon that handles cryptographic key establishment and manages IPsec VPN negotiations over the IKEv1 and IKEv2 protocols.

Exploitable without authentication, the three security defects are a heap buffer overflow (CVE-2026-19313), a stack-based buffer overflow (CVE-2026-19318), and a type confusion (CVE-2026-19315).

Attackers could send specially crafted network traffic to trigger each of these vulnerabilities and achieve RCE, WatchGuard says.

WatchGuard also patched a critical stack-based buffer overflow bug (CVE-2026-13086) in the Endpoint Protection Manager (epm) service that is used by the deprecated Mobile Security feature in Fireware OS, which could lead to RCE.

Additionally, the company fixed CVE-2026-78174 in WatchGuard Dimension, which could allow low-privileged administrators to extract a super admin’s session ID and CSRF tokens and take over their account.

Advertisement. Scroll to continue reading.

All five security defects have a CVSS score of 9.3. Fixes for them were included in Fireware OS versions 2026.2.2, 12.12.2, and 12.5.20, and Dimension version 2.3.1.

The updates also resolve seven high-severity Fireware OS vulnerabilities that could lead to denial-of-service (DoS), including six impacting the iked process, and five high-severity Dimension bugs leading to arbitrary command execution, tampering with the global administrator’s passphrase, and DoS.

Patches were also rolled out for 11 medium-severity vulnerabilities, including one in Fireware OS’s iked process and 10 in Dimension.

WatchGuard says it is not aware of any of these security defects being exploited in the wild. Additional information can be found on the company’s security advisories page.

Related: PaperCut Exploitation Escalates to Active Intrusions

Related: Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit

Related: ServiceNow Patches 3 Critical Code Injection Vulnerabilities

Related: Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

Related Content

Artificial Intelligence

Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely.

Vulnerabilities

Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure.

Vulnerabilities

CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog.

Endpoint Security

Kaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product.

Vulnerabilities

Attackers could exploit the security defects to execute arbitrary code and access or tamper with data.

Vulnerabilities

Named KindaRails2Shell, the arbitrary file read flaw allows attackers to extract secrets and execute arbitrary code remotely.

Vulnerabilities

PaperCut has released a second emergency patch for the exploited vulnerabilities, which are now tracked as CVE-2026-82078 and CVE-2026-81578.

Artificial Intelligence

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version