CVE-2026-19318
Deferred Deferred - Pending Action

Stack-Based Buffer Overflow in WatchGuard Fireware OS

Vulnerability report for CVE-2026-19318, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-09-03

Assigner: WatchGuard Technologies, Inc.

Description

A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-09-03
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
watchguard fireware_os From 2025.0 (inc) to 2026.2.2 (exc)
watchguard fireware_os From 12.0 (inc) to 12.12.2 (exc)
watchguard fireware_os 12.5.*
watchguard fireware_os 12.12.2
watchguard fireware_os 2026.2.2
watchguard fireware_os 12.5.20

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-191 The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
CWE-129 The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stack-based buffer overflow in WatchGuard Fireware OS's iked process. A remote attacker can send a specially crafted IKE_AUTH message with an undersized EAP-MSCHAPv2 payload length field. This triggers a stack overflow, potentially allowing arbitrary code execution. Exploitation requires IKE payload diagnostic logging to be enabled.

Detection Guidance

To detect this vulnerability, monitor for crashes in the iked process on WatchGuard Fireware OS devices. Check if IKE payload diagnostic logging is enabled, as exploitation requires this setting. Inspect network traffic for malformed IKE_AUTH messages with undersized EAP-MSCHAPv2 length fields.

Impact Analysis

An attacker could crash the device, causing a denial-of-service. In some cases, they might execute arbitrary code on the system, leading to full compromise. This requires network access and specific logging enabled, but could disrupt operations or allow unauthorized access.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling remote code execution and denial-of-service attacks on affected WatchGuard Fireware OS devices. Exploitation may lead to unauthorized access to sensitive data, violating confidentiality requirements under these regulations. The lack of authentication required for exploitation increases the risk of data breaches.

Mitigation Strategies

Immediately update affected WatchGuard Fireware OS versions to patched releases: 2026.2.2, 12.12.2, or 12.5.20. Disable IKE payload diagnostic logging if enabled. Block external access to IKE ports until patched. Monitor for unusual network traffic patterns targeting IKE ports.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19318. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart