CVE-2026-19317
Deferred Deferred - Pending Action

Out-of-Bounds Read in WatchGuard Fireware OS VPN Processing

Vulnerability report for CVE-2026-19317, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-09-03

Assigner: WatchGuard Technologies, Inc.

Description

An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-09-03
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
watchguard fireware_os From 2025.0 (inc) to 2026.2.2 (exc)
watchguard fireware_os From 12.0 (inc) to 12.12.2 (exc)
watchguard fireware_os From 12.0 (inc) to 12.5.20 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-191 The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an out-of-bounds read vulnerability in WatchGuard Fireware OS's iked process. A remote unauthenticated attacker can send specially crafted network traffic to trigger a segmentation fault in the iked daemon, causing it to crash and respawn. This leads to a denial-of-service condition for IPSec VPN services using IKEv2.

Detection Guidance

Monitor for crashes in the iked process on WatchGuard Fireware OS devices. Check logs for segmentation faults or unexpected respawns of the iked daemon. Use network traffic analysis tools to detect malformed IKEv2 messages targeting VPN services.

Impact Analysis

The vulnerability can disrupt VPN services, including Mobile User VPN and Branch Office VPN, by crashing the iked daemon. This results in a temporary loss of VPN connectivity until the daemon respawns. Affected Fireware OS versions are between 2025.0 and below 2026.2.2, 12.0 and below 12.12.2, and 12.0 and below 12.5.20.

Compliance Impact

This vulnerability causes a denial-of-service condition in VPN services, which could disrupt secure data transmission and access controls required by standards like GDPR and HIPAA. A DoS condition may lead to unauthorized data exposure or loss of availability, potentially violating compliance requirements for data protection and secure communications.

Mitigation Strategies

Upgrade Fireware OS to versions 2026.2.2, 12.12.2, or 12.5.20 or later. If immediate upgrade is not possible, restrict access to IKEv2 VPN services via firewall rules until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19317. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart