Skip to content
WatchGuard Firebox Patches Third Critical IKEv2 RCE in 10 Months, T15/T35 Still Exposed

WatchGuard Firebox Patches Third Critical IKEv2 RCE in 10 Months, T15/T35 Still Exposed

Techtimes • July 4, 2026

WatchGuard Technologies released patches on July 2 for a critical pre-authentication remote code execution vulnerability in every supported Firebox firewall model — the third critical flaw discovered in the same VPN daemon in roughly ten months, and one with no fix yet available for two legacy hardware tiers. Network administrators running Firebox appliances should treat the update as urgent: the two prior flaws of the same class were actively exploited within weeks of disclosure, leaving more than 100,000 devices exposed across both incidents.

The flaw, tracked as CVE-2026-13368 , carries a CVSS 4.0 score of 9.2 and stems from a race condition in the LDAP authentication path of Mobile User VPN with IKEv2 that produces a use-after-free memory corruption condition. A remote, unauthenticated attacker can time a malicious request to corrupt memory during the LDAP authentication handshake, gaining arbitrary code execution in the context of the iked process — the Internet Key Exchange daemon that manages all VPN tunnel negotiations on the appliance, running with elevated privileges and exposed directly to the internet.

Patches are available in Fireware OS versions 2026.2.1 and 12.12.1. T15 and T35 models on the 12.5.x branch have no resolved version. Fireware OS 11.x, which has reached end of life, receives no patch.

The vulnerability lives at the intersection of two difficult bug classes: a race condition and a use-after-free.

IKEv2 — the Internet Key Exchange version 2 protocol defined in RFC 7296 — runs the authentication negotiation for every VPN tunnel the Firebox handles. On Firebox appliances configured to authenticate Mobile User VPN clients against an external LDAP directory, the iked process must reach out to that LDAP server during the IKE_AUTH phase before authentication completes. CVE-2026-13368 exploits the timing window in that handshake: by sending a crafted request that races with the LDAP lookup, an attacker can cause the iked process to access memory that has already been freed. If the attacker controls the data placed in that freed memory region — the defining characteristic of a use-after-free exploit — the result is arbitrary code execution.

Because the IKEv2 negotiation phase is fully accessible to unauthenticated network traffic — that is precisely how the protocol is designed to work, establishing trust before identity is verified — there is no authentication barrier between an attacker on the internet and the vulnerable code path. The CVSS 4.0 vector encodes this directly: AV:N (network-accessible), PR:N (no privileges required), UI:N (no user interaction). The AT:P (attack preconditions: present) score reflects the one requirement that limits the exposed population: the Firebox must be configured to authenticate Mobile User VPN with IKEv2 against an external LDAP server. Organizations using local authentication or a different VPN method are not affected.

The iked daemon runs with elevated privileges and holds locally stored secrets including VPN keys. A successful compromise does not merely give an attacker a foothold on the appliance — it gives them the equivalent of administrative control over the network perimeter itself.

CVE-2026-13368 is not an isolated defect. It is the third critical pre-authentication RCE discovered in the Firebox IKEv2 VPN stack since September 2025, and the pattern matters for how defenders should read the disclosure.

In September 2025, WatchGuard patched CVE-2025-9242 , an out-of-bounds write vulnerability in the iked process with a CVSS score of 9.3. WatchGuard disclosed it without exploitation evidence at the time. Within a month, the company had updated the advisory to confirm active exploitation, and the Shadowserver Foundation's internet-wide scans found more than 73,800 Firebox devices still unpatched — most of them in North America and Europe. CISA added CVE-2025-9242 to its Known Exploited Vulnerabilities catalog and ordered federal civilian agencies to remediate it.

In December 2025, WatchGuard disclosed CVE-2025-14733 , a second out-of-bounds write in the same iked process, this time affecting both Mobile User VPN and Branch Office VPN configurations using IKEv2 dynamic gateway peers. CVSS score: 9.3. WatchGuard confirmed active exploitation on the day of the advisory — this one was not a theoretical risk at disclosure but an already-weaponized zero-day. Shadowserver scans found approximately 124,658 exposed Firebox devices by the weekend following the advisory's release, with more than 35,000 in the United States alone. CISA added CVE-2025-14733 to the KEV catalog the following day and ordered federal agencies to patch within a week.

CVE-2025-14733's exploitation indicators are instructive for defenders watching the new advisory. During a successful exploit, the iked process hangs — interrupting VPN tunnel negotiations and rekeying, which is a strong indicator of attack. After a failed or successful exploit, the iked process crashes and generates a fault report. WatchGuard provided four attacker-controlled IP addresses as indicators of compromise for that campaign, and also identified a specific log pattern: an IKE_AUTH request with a CERT payload larger than 2,000 bytes as a strong attack indicator — details documented in the WGSA-2025-00027 advisory .

Cybersecurity Dive reported that Caitlin Condon, vice president of security research at VulnCheck, noted after CVE-2025-14733's disclosure that memory corruption flaws of this class are valuable to adversaries because successful exploitation usually allows for high-privileged remote code execution, but also carry a practical constraint: they can be tricky to exploit and sometimes require per-target knowledge — such as hard-coded memory addresses — to build a stable exploit.

The technical difference between CVE-2025-14733 (out-of-bounds write requiring dynamic gateway peer configuration) and CVE-2026-13368 (race condition use-after-free requiring external LDAP) means each flaw has a distinct attack surface, even though both live in the same iked daemon. An organization may be exempt from one while being exposed by the other depending on its VPN configuration choices. The current absence of confirmed exploitation for CVE-2026-13368 should be read in light of the prior two bugs: both were quickly weaponized after disclosure.

One aspect of the July 2 advisory that warrants separate attention is the explicit unresolved status for two hardware lines. WatchGuard's resolution table shows:

Fireware OS 2025.1.x: resolved in 2026.2.1 Fireware OS 12.x (most models): resolved in 12.12.1 Fireware OS 12.5.x (T15 and T35 models): Unresolved Fireware OS 11.x: End of Life — no patch

T15 and T35 customers on the 12.5.x branch face an indefinite window of exposure with no patch and, per the advisory, no listed workaround. WatchGuard's advisory page for WGSA-2026-00023 is the authoritative source to monitor for any update. Until a resolved version is published, organizations running those models should evaluate whether compensating controls — isolating the VPN interface, disabling LDAP-based IKEv2 authentication if operationally feasible, or accelerating hardware refresh — are appropriate.

Fireware OS 11.x users have a different problem: the 11.x branch has reached end of life with no patch path for any vulnerability, including CVE-2026-13368. This is not merely a security best-practice issue. In February 2026, CISA issued Binding Operational Directive 26-02 , which requires all Federal Civilian Executive Branch agencies to identify and remediate end-of-support edge devices — including those running software no longer maintained by the vendor — within one year. Any FCEB agency or contractor running Firebox OS 11.x is operating an end-of-support edge device under an enforceable compliance obligation, not a recommendation. Migration to a supported Firebox platform is a regulatory requirement, not just a security best practice.

WatchGuard's Firebox line is used by more than 250,000 small and medium-sized enterprises worldwide through a network of roughly 17,000 security resellers and managed service providers. The appliances sit at the outermost boundary of those networks, and the VPN services they provide are by design exposed to the public internet — there is no interior hop that might absorb a pre-authentication attack.

An unauthenticated RCE on a perimeter firewall is categorically different from a vulnerability inside a network. The attacker needs only network connectivity to the device's VPN port, which is typically open to the entire internet. No credentials, no phishing campaign, no prior foothold inside the organization.

WatchGuard's own analysis of what successful exploitation of CVE-2025-14733 enabled makes the consequence concrete: interception and manipulation of secure communications via IKEv2 VPN, theft of locally stored secrets, lateral movement deeper into enterprise environments, and persistent manipulation of firewall policies to maintain access. Those same consequences apply to CVE-2026-13368 exploited against the iked process.

SME environments face compounded risk. Organizations that rely on managed service providers for firewall management frequently have firmware update cycles measured in days or weeks rather than hours — a gap that threat actors demonstrated they are prepared to exploit at scale during the prior campaigns.

The full affected product list covers virtually every Firebox appliance across the active product range, as detailed in the WGSA-2026-00023 advisory :

Fireware OS 2025.1.x (resolved in 2026.2.1): T115-W, T125, T125-W, T145, T145-W, T185, M295, M395, M495, M595, M695

Fireware OS 12.x (resolved in 12.12.1): T20, T25, T40, T45, T55, T70, T80, T85, M270, M290, M370, M390, M470, M570, M590, M670, M690, M440, M4600, M4800, M5600, M5800, Firebox Cloud, Firebox NV5, FireboxV

Fireware OS 12.5.x (T15 and T35 only — no resolved version): T15, T35

Fireware OS 11.x: End of Life — no patch available for any model

Organizations using FireboxV or Firebox Cloud virtual platforms are also affected; those running the 12.x line should update to 12.12.1.

No temporary workaround is listed in the advisory for CVE-2026-13368 — unlike CVE-2025-14733, which provided a workaround for organizations using only static BOVPN gateway peer configurations. Firmware upgrade is the only reliable remediation path.

For most Firebox models: Update immediately to Fireware OS 2026.2.1 (for T115-W, T125-series, T145-series, T185, M295, M395, M495, M595, M695) or 12.12.1 (for the full 12.x hardware range listed above). Firmware is available at the WatchGuard Software Downloads center .

For T15 and T35 on Fireware OS 12.5.x: No resolved version is available. Monitor WGSA-2026-00023 for updates. In the interim, assess whether disabling external LDAP authentication for Mobile User VPN with IKEv2 is operationally feasible as a compensating control. Evaluate whether the hardware's ongoing vulnerability to repeated critical iked flaws warrants an accelerated refresh cycle. No workaround is listed in the advisory.

For any Firebox on Fireware OS 11.x: Migrate to supported hardware and software. This is now a regulatory compliance obligation for FCEB agencies and their contractors under BOD 26-02, in addition to the immediate security risk.

Check LDAP configuration first: CVE-2026-13368's attack surface is specific: Mobile User VPN with IKEv2 must be configured to use an external LDAP authentication server. Organizations using local authentication or an alternative external authentication method for IKEv2 mobile users face reduced but not necessarily zero risk, given the broader exploitation history of the iked process across multiple CVEs. Audit your VPN authentication configuration and treat the patch as a priority regardless.

Review prior patch status: If CVE-2025-9242 or CVE-2025-14733 have not been fully remediated, those vulnerabilities represent active risks. Any organization that confirmed threat actor activity during the December 2025 campaign should rotate all locally stored secrets on the affected Firebox appliances, per WatchGuard's post-exploitation guidance.

The full advisory, resolution table, and affected product list are available at WatchGuard's PSIRT portal under advisory ID WGSA-2026-00023 .

The vulnerability affects all Firebox appliances running the affected Fireware OS versions, but the exploitable condition requires a specific configuration: Mobile User VPN with IKEv2 must be set to authenticate against an external LDAP server. Organizations using local authentication for Mobile User VPN with IKEv2, or those not using IKEv2 for mobile users at all, have a reduced attack surface. That said, the iked process handles all IKE negotiations on the appliance and has been the site of three critical vulnerabilities in ten months; patching to 2026.2.1 or 12.12.1 is the only way to eliminate the risk from this CVE and prior related bugs simultaneously.

WatchGuard's advisory shows the T15 and T35 models, which run on the Fireware OS 12.5.x branch, have no resolved version for CVE-2026-13368. No explanation or timeline has been published for the gap. Until a patch is available, T15 and T35 owners should consider disabling external LDAP authentication for Mobile User VPN with IKEv2 if operationally feasible, monitor WatchGuard's WGSA-2026-00023 advisory page for updates, and evaluate whether the hardware's ongoing vulnerability to repeated critical iked flaws warrants an accelerated refresh cycle. No workaround is listed in the advisory.

No confirmed active exploitation has been reported as of July 4, 2026. The advisory does not include indicators of compromise and does not state that exploitation has been observed. That absence of confirmed exploitation is important context — but so is the pattern from the two prior bugs: CVE-2025-9242 had no confirmed exploitation at disclosure and was actively exploited within a month; CVE-2025-14733 was already being exploited when WatchGuard disclosed it. Both were added to CISA's Known Exploited Vulnerabilities catalog. A lack of current exploitation evidence for CVE-2026-13368 is not a reason to delay patching.

Binding Operational Directive 26-02, issued by CISA in February 2026, requires all Federal Civilian Executive Branch agencies to identify and address end-of-support edge devices — hardware or software that no longer receives security updates from the vendor — within one year. Fireware OS 11.x has reached end of life with no patch path for any vulnerability, including CVE-2026-13368. Federal agencies and their contractors running Firebox hardware on OS 11.x are operating devices that fall directly within BOD 26-02's scope. Migration to supported hardware is a compliance requirement. Private-sector organizations are not bound by the directive, but CISA explicitly recommends that private organizations review its guidance and address end-of-support edge device risk in their own infrastructure.