Skip to content

Warning: Multiple Vulnerabilities in WatchGuard Fireware OS, Patch Immediately!

Ccb.Belgium.Be August 28, 2026

Multiple vulnerabilities exist in the WatchGuard Fireware OS which is used in internet edge devices such as firewalls. This makes these vulnerabilities vital to remediate since firewalls have a critical function to protect networks for malicious traffic. Attackers will target these vulnerable devices to gain initial access into a corporate network. These vulnerabilities have a high impact on the confidentiality, integrity and availability of the affected system. A vulnerability also exists in WatchGuard Dimension which allows low privileged administrators to perform account takeover on high privileged accounts. This vulnerability has a high impact on the confidentiality, integrity and no impact on the availability.

CVE-2026-19313 is a heap overflow vulnerability in the WatchGuard Fireware OS iked process which allows remote unauthenticated attackers to perform arbitrary code execution by sending specially crafted network traffic.

CVE-2026-19318 is a stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process which allows remote unauthenticated attackers to perform arbitrary code execution by sending specially crafted network traffic.

CVE-2026-13086 is a stack-based buffer overflow in the epm (Endpoint Protection Manager) service that is used by the deprecated Mobile Security feature in WatchGuard Fireware OS which allows unauthenticated remote attackers to perform arbitrary code execution.

CVE-2026-19315 is a type confusion vulnerability in the iked process of WatchGuard Fireware OS which allows a remote unauthenticated attacker to perform arbitrary code execution by sending specially crafted network traffic.

CVE-2026-78174 is a vulnerability in WatchGuard Dimension which logs unredacted session identifiers for logged-in users in its web UI diagnostic log, enabling low-privileged Dimension administrators to retrieve this log and extract higher privileged administrators session tokens. Resulting in an account takeover.

The Centre for Cybersecurity Belgium strongly recommends installing updates for vulnerable devices with the highest priority after thorough testing.

The CCB recommends organizations upscale monitoring and detection capabilities to identify any related suspicious activity and ensure a swift response in case of an intrusion. In case of an intrusion, you can report an incident via . While patching appliances or software to the newest version may protect against future exploitation, it does not remediate historic compromise.