CVE-2026-78011
8.7WatchGuard · Fireware OS
An integer underflow in WatchGuard Fireware OS allows remote unauthenticated attackers to trigger a Denial of Service condition in VPN processing via crafted network traffic.
Executive summary
A critical integer underflow vulnerability in WatchGuard Fireware OS allows remote, unauthenticated attackers to crash VPN services, leading to significant network availability risks.
Vulnerability
This is an integer underflow flaw (CWE-191) residing in the iked process. It allows an unauthenticated remote attacker to disrupt VPN operations by sending specially crafted network packets to the affected device.
Business impact
The vulnerability carries a CVSS score of 8.7, reflecting its high potential for service disruption. Successful exploitation results in a Denial of Service condition, which can disable secure remote access for employees and branch offices, causing immediate operational downtime and potential loss of productivity.
Remediation
Immediate Action: Update Fireware OS to version 2026.2.2, 12.12.2, or 12.5.20 as applicable to your specific deployment.
Proactive Monitoring: Monitor VPN gateway logs for repeated connection failures or unusual traffic spikes targeting the iked process that may precede a service crash.
Compensating Controls: Restrict inbound access to VPN management and service ports to known, trusted IP addresses using access control lists to reduce the attack surface.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS severity and the critical role of VPN gateways in infrastructure, this vulnerability presents a significant availability risk. Security teams should prioritize patching affected Fireware OS devices during the next maintenance window to prevent potential service outages caused by malicious actors.
More WatchGuard CVEs
Sources
Originally found and disclosed by Discovered Internally by WatchGuard AI Security Research, per the CVE Program record.