CVE-2026-19317
8.7WatchGuard · Fireware OS
An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows remote unauthenticated attackers to trigger a denial of service in VPN processing via crafted network traffic.
Executive summary
A critical out-of-bounds read vulnerability in WatchGuard Fireware OS enables remote, unauthenticated attackers to disrupt VPN services through a denial of service condition.
Vulnerability
The flaw exists within the iked process, which manages internet key exchange for VPN tunnels. An unauthenticated remote attacker can send specifically crafted network packets to trigger an out-of-bounds read, causing the service to crash and resulting in a denial of service.
Business impact
The ability for an unauthenticated attacker to remotely crash VPN processing poses a significant risk to organizational connectivity and remote access infrastructure. With a CVSS score of 8.7, this vulnerability is classified as high severity because it directly impacts the availability of secure communications, potentially leading to business disruption and loss of workforce productivity.
Remediation
Immediate Action: Upgrade all affected WatchGuard Fireware OS installations to version 2026.2.2, 12.12.2, or 12.5.20 immediately.
Proactive Monitoring: Monitor firewall logs for anomalous iked process behavior or high volumes of malformed traffic directed at VPN endpoints.
Compensating Controls: Implement rate limiting on VPN gateway interfaces to mitigate the impact of potential flood-based exploits until the patch is applied.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the remote nature of this vulnerability and the critical role of VPN gateways in network security, administrators should prioritize patching as a matter of urgency. By updating to the versions specified in the vendor solution, organizations can effectively eliminate the risk of service disruption caused by this out-of-bounds read flaw.
More WatchGuard CVEs
Sources
Originally found and disclosed by McCaulay Hudson (@_McCaulay) of watchTowr, per the CVE Program record.