Critical RCE Vulnerabilities in WatchGuard Fireware VPNs Disclosed

Critical RCE Vulnerabilities in WatchGuard Fireware VPNs Disclosed

First seen 28 Aug 2026, 19:19 UTC Feedlymallory.aicvefeed.iovulners.com 60.8

Article Content

Browse articles
ThreatCluster

On August 28, 2026, WatchGuard disclosed five critical vulnerabilities in Fireware OS and WatchGuard Dimension, including CVE-2026-19318, a pre-authentication stack buffer overflow in the iked VPN daemon. This flaw allows unauthenticated attackers to execute arbitrary code by sending specially crafted VPN traffic, with a CVSS score of 9.3. The vulnerabilities affect multiple versions of Fireware OS and WatchGuard Dimension, posing a significant risk to organizations using these products. No confirmed exploitation or public proof-of-concept code has been reported, but immediate patching is advised. WatchGuard has released updates to address these vulnerabilities, and organizations are urged to limit access to affected interfaces until patches are applied.

Key Points: • CVE-2026-19318 allows unauthenticated remote code execution via crafted VPN traffic. • Five critical vulnerabilities in WatchGuard Fireware OS and Dimension have been disclosed. • Immediate patching is recommended as no exploitation has been confirmed yet.

Timeline

2026-08-27
CVE-2026-19318 published
A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process was published, allowing remote code execution.
cvefeed.io
2026-08-28
WatchGuard discloses vulnerabilities
WatchGuard announced five critical vulnerabilities in Fireware OS and Dimension, urging immediate updates.
mallory.ai
2026-08-28
Patches released
Updates for affected versions of Fireware OS and WatchGuard Dimension were released to mitigate the vulnerabilities.
mallory.ai