CVE-2026-81851
Deferred Deferred - Pending Action

Heap Overflow in Fireware OS iked Process

Vulnerability report for CVE-2026-81851, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-28

Assigner: WatchGuard Technologies, Inc.

Description

A heap-based buffer overflow vulnerability in Fireware OS's iked process allows an authenticated administrator to crash the IKE daemon (iked), resulting in a denial of service, by saving a specially crafted configuration.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-28
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
watchguard fireware_os From 2025.0 (inc) to 2026.2.1 (inc)
watchguard fireware_os From 12.0 (inc) to 12.12.1 (inc)
watchguard fireware_os *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a heap-based buffer overflow in Fireware OS's iked process. An authenticated administrator can trigger it by saving a specially crafted configuration, causing heap memory corruption in the IKE daemon. This leads to a crash of the iked process, resulting in a denial of service.

Detection Guidance

Detecting this vulnerability requires checking the Fireware OS version on your WatchGuard device. Use the administrative interface or CLI to verify if your version falls within the affected ranges (2025.0 to 2026.2.1, 12.0 to 12.12.1, etc.). No specific commands are provided in the context for direct detection.

Impact Analysis

The primary impact is a denial of service due to the iked process crashing. While code execution is theoretically possible, it would require significant additional effort to exploit. The vulnerability affects specific Fireware OS versions, so systems running vulnerable versions are at risk.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR, HIPAA, or similar standards as it primarily causes a denial of service through a heap-based buffer overflow in Fireware OS. However, if exploited, it could disrupt network services, potentially affecting data availability which may indirectly impact compliance with availability requirements in regulations like GDPR or HIPAA.

Mitigation Strategies

Immediately update Fireware OS to a patched version (2026.2.1, 12.12.1, 12.11.9, or 12.5.18). Restrict administrative access to trusted users only to prevent exploitation. Monitor the iked process for crashes or unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81851. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart