CVE-2026-78010
8.7WatchGuard · Fireware OS
A stack-based buffer overflow in the WatchGuard Fireware OS iked process allows remote unauthenticated attackers to cause a Denial of Service condition in VPN processing.
Executive summary
A high-severity buffer overflow vulnerability in WatchGuard Fireware OS permits unauthenticated remote attackers to crash VPN services, leading to significant network disruption.
Vulnerability
This is a stack-based buffer overflow (CWE-121) located in the iked process of the VPN subsystem. The flaw is remotely exploitable by an unauthenticated attacker who can send specially crafted network packets to trigger a service crash.
Business impact
Successful exploitation results in a Denial of Service for critical VPN infrastructure, which can halt remote access for employees and disrupt site-to-site connectivity. Given the CVSS score of 8.7, this vulnerability represents a high risk to business continuity, as it allows an external actor to disable security appliances without requiring valid credentials.
Remediation
Immediate Action: Update affected Fireware OS appliances to the patched versions: 2026.2.2, 12.12.2, or 12.5.20.
Proactive Monitoring: Monitor firewall system logs for irregular iked process crashes or unexpected service restarts that may indicate exploitation attempts.
Compensating Controls: Restrict access to the VPN management interface and IKE ports to known, trusted IP addresses using upstream access control lists where possible.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing WatchGuard Fireware OS should prioritize this update as part of their immediate maintenance cycle. Because the vulnerability allows for unauthenticated disruption of network services, applying the vendor-provided patches is the only definitive way to eliminate the risk of service interruption by remote actors.
More WatchGuard CVEs
Sources
Originally found and disclosed by Discovered Internally by WatchGuard AI Security Research, per the CVE Program record.