CVE-2026-19314
8.7WatchGuard · Fireware OS
A remote unauthenticated integer underflow vulnerability in the WatchGuard Fireware OS iked process allows attackers to trigger a Denial of Service condition in VPN processing.
Executive summary
A remote, unauthenticated integer underflow vulnerability in WatchGuard Fireware OS permits attackers to disrupt VPN services, posing a high risk to network availability.
Vulnerability
This vulnerability involves an integer underflow within the iked process, which is responsible for IKE daemon operations. An unauthenticated remote attacker can exploit this by sending specially crafted network traffic to the device, leading to a system crash or service disruption.
Business impact
The exploitation of this flaw results in a Denial of Service for VPN connectivity, which can severely impact remote workforce operations and secure site to site communication. With a CVSS score of 8.7, this vulnerability is classified as high severity, reflecting the ease of exploitation and the significant operational disruption it causes to critical network infrastructure.
Remediation
Immediate Action: Update Fireware OS to version 2026.2.2, 12.12.2, or 12.5.20 as applicable to your hardware deployment.
Proactive Monitoring: Monitor firewall system logs and VPN gateway health metrics for unexpected restarts or service interruptions in the iked process.
Compensating Controls: While a patch is available, organizations should restrict access to VPN management interfaces to trusted IP addresses where possible to reduce the attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the critical nature of VPN gateways in maintaining secure network perimeters, immediate patching is essential to prevent service outages. Administrators should prioritize these updates during the next maintenance window to ensure the continued stability and availability of their network security infrastructure.
More WatchGuard CVEs
Sources
Originally found and disclosed by McCaulay Hudson (@_McCaulay) of watchTowr, per the CVE Program record.