CVE-2026-19316
8.7WatchGuard · Fireware OS
A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to trigger a Denial of Service condition in VPN processing.
Executive summary
A remote, unauthenticated double-free vulnerability in WatchGuard Fireware OS permits attackers to disrupt VPN services via specially crafted network traffic, posing a high availability risk.
Vulnerability
The vulnerability exists within the iked process, which manages Internet Key Exchange operations. An unauthenticated attacker can exploit this double-free flaw by sending malformed network packets to the VPN service, resulting in a system crash or service disruption.
Business impact
The exploitation of this vulnerability leads to a Denial of Service condition, which can effectively disconnect remote users and branch offices from the corporate network. Given the CVSS score of 8.7, this flaw represents a significant risk to business continuity, as it allows attackers to disrupt critical infrastructure without requiring any prior authentication or user interaction.
Remediation
Immediate Action: Update WatchGuard Fireware OS to version 2026.2.2, 12.12.2, or 12.5.20 as specified in the vendor security advisory.
Proactive Monitoring: Monitor VPN gateway logs for unusual traffic patterns or frequent service restarts associated with the iked process.
Compensating Controls: While a direct patch is the only permanent solution, ensure the management interface of the appliance is not exposed to the public internet to limit the attack surface.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit available.
Analyst recommendation
This vulnerability presents a high risk to network availability and should be addressed as a priority. Administrators must schedule maintenance windows to apply the prescribed firmware updates immediately to prevent potential service outages caused by exploitation of the iked process.
More WatchGuard CVEs
Sources
Originally found and disclosed by McCaulay Hudson (@_McCaulay) of watchTowr, per the CVE Program record.