CVE-2026-86133
Received Received - Intake

Integer Underflow in WatchGuard Fireware OS IKE Daemon

Vulnerability report for CVE-2026-86133, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: WatchGuard Technologies, Inc.

Description

An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message, resulting in a denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
watchguard fireware_os From 2026.3 (inc) to 2026.3.2 (exc)
watchguard fireware_os From 2025.0 (inc) to 2026.2.3 (exc)
watchguard fireware_os From 12.0 (inc) to 12.12.3 (exc)
watchguard fireware_os From 12.0 (inc) to 12.5.21 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
CWE-191 The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an integer underflow flaw in WatchGuard Fireware OS's IKE daemon (iked). It allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message. This results in a denial of service for the affected system.

Detection Guidance

Detecting this vulnerability requires monitoring for crashes in the iked process or unusual IKEv2 handshake failures. WatchGuard Fireware OS logs should be checked for iked crashes or malformed IKEv2 messages. Network traffic analysis tools can inspect IKEv2 packets for anomalies. No specific commands are provided in the context.

Impact Analysis

The vulnerability can cause the iked process to crash, leading to a denial of service. This means network services relying on IKEv2 may become unavailable, disrupting VPN connections and other security-related functions.

Compliance Impact

This vulnerability causes a denial of service by crashing the iked process, which could disrupt network security operations. For GDPR, it may impact availability of security systems processing personal data. For HIPAA, it could affect the integrity and availability of protected health information systems.

Mitigation Strategies

Immediately update Fireware OS to versions 2026.3.2, 2026.2.3, 12.12.3, or 12.5.21. Block or restrict IKEv2 traffic from untrusted sources if updates are not immediately possible. Monitor for exploitation attempts and iked crashes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86133. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart