CVE-2026-19313
Deferred Deferred - Pending Action

Heap Overflow in WatchGuard Fireware OS

Vulnerability report for CVE-2026-19313, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-09-03

Assigner: WatchGuard Technologies, Inc.

Description

An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-09-03
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
watchguard fireware_os From 2025.0 (inc) to 2026.2.2 (exc)
watchguard fireware_os From 12.0 (inc) to 12.12.2 (exc)
watchguard fireware_os to 12.5.20 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-680 The product performs a calculation to determine how much memory to allocate, but an integer overflow can occur that causes less memory to be allocated than expected, leading to a buffer overflow.
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a heap overflow vulnerability in WatchGuard Fireware OS's iked process. A remote attacker can send specially crafted network traffic to trigger a buffer overflow, potentially allowing arbitrary code execution without authentication. The flaw exists due to improper handling of data in memory, causing crashes or remote code execution.

Detection Guidance

To detect this vulnerability, check your Fireware OS version against affected releases (2025.0 to below 2026.2.2, 12.0 to below 12.12.2, or T15/T35 models below 12.5.20). Monitor network traffic for crashes or unusual patterns targeting the iked process.

Impact Analysis

If exploited, this vulnerability could allow an attacker to crash your system, disrupt services, or take full control of affected devices. Unpatched systems running vulnerable Fireware OS versions are at risk. The impact includes denial of service and potential remote code execution.

Compliance Impact

This vulnerability could potentially lead to unauthorized access or data breaches due to remote code execution, which may violate compliance requirements under GDPR or HIPAA if sensitive data is exposed or compromised.

Mitigation Strategies

Immediately update Fireware OS to versions 2026.2.2, 12.12.2, or 12.5.20 or later. If updates are not possible, restrict network access to the iked process and monitor for exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19313. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart