Skip to content

PSIRT WatchGuard CVE-2026-19313

psirt.watchguard.com • August 29, 2026

An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

Impact: An unauthenticated remote attacker can trigger a heap buffer overflow in the IKE daemon, causing a crash and denial of service, with the potential for remote code execution due to attacker-controlled data being written beyond the bounds of the allocated buffer.

Extracted Entities