Skip to content
CVE-2026-19318 - Exploits & Severity

CVE-2026-19318 - Exploits & Severity

Feedly • August 28, 2026

Stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process that allows remote code execution through specially crafted network traffic.

An unauthenticated attacker over the network can send specially crafted packets to the iked process to execute arbitrary code on the affected WatchGuard firewall.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Apply the available security patch from WatchGuard for Fireware OS to address the stack-based buffer overflow in the iked process. Restrict network access to the iked process if possible through network segmentation or firewall rules while patches are being deployed.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Feedly found the first article mentioning CVE-2026-19318 . See article

NVD published the first details for CVE-2026-19318

A CVSS base score of 9.3 has been assigned.

GitHub Advisories released a security advisory .

Critical Pre-Authentication RCE Flaws Expose WatchGuard Fireware VPNs

CVE-2026-19313 (CVSS 9.3): WatchGuard Fireware Pre-Authentication Remote Code Execution Flaws Patched

CVE-2026-19318 - Fireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Code Execution

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities