CVE-2026-78009

8.7

WatchGuard · Fireware OS

A remote, unauthenticated out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process enables attackers to trigger a Denial of Service condition in VPN processing.

Executive summary

A critical out-of-bounds read vulnerability in WatchGuard Fireware OS allows unauthenticated remote attackers to disrupt VPN services via a Denial of Service attack.

Vulnerability

The vulnerability exists within the iked process, which is responsible for Internet Key Exchange (IKE) operations. An unauthenticated remote attacker can exploit this flaw by sending specially crafted network traffic to the device, leading to a crash of the VPN processing service.

Business impact

The ability for an unauthenticated attacker to force a Denial of Service condition on VPN infrastructure presents a significant risk to organizational availability. Given the CVSS score of 8.7, this vulnerability is classified as High severity because it allows for remote disruption of secure remote access tunnels, potentially isolating remote workers or branch offices from the internal network.

Remediation

Immediate Action: Update Fireware OS to version 2026.2.2, 12.12.2, or 12.5.20 as specified in the vendor security advisory.

Proactive Monitoring: Monitor firewall system logs for repeated iked service crashes or unusual spikes in malformed IKE traffic patterns.

Compensating Controls: Implement strict access control lists on the firewall external interface to limit IKE traffic to known and trusted peer IP addresses where possible.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for complete disruption of VPN connectivity, organizations must prioritize patching their WatchGuard appliances. Apply the recommended firmware updates during the next available maintenance window to ensure the stability and security of remote access infrastructure.

More WatchGuard CVEs

Sources

Originally found and disclosed by Discovered Internally by WatchGuard AI Security Research, per the CVE Program record.