Skip to content
ThreatCluster

Stack-Based Buffer Overflow Vulnerabilities in WatchGuard Fireware OS

First seen 30 Sep 2026, 21:37 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 22:31 UTC
  • •CVE-2026-81433 allows unauthenticated adjacent network access exploitation.
  • •CVE-2026-18145 requires authenticated admin privileges for exploitation.
  • •Both vulnerabilities could lead to service crashes or arbitrary code execution.

Two stack-based buffer overflow vulnerabilities have been identified in WatchGuard Fireware OS. CVE-2026-81433 affects the DHCP fingerprinting daemon, allowing unauthenticated attackers with adjacent network access to execute arbitrary code or crash the process through specially crafted DHCP packets. CVE-2026-18145 impacts the spamBlocker service, permitting authenticated attackers with admin privileges to crash the service or execute arbitrary code via crafted management requests. Both vulnerabilities pose significant risks to users of WatchGuard Fireware OS. The vulnerabilities have been disclosed today, and further details are available on the CVE database. No patches have been mentioned in the articles, indicating that these vulnerabilities may still be.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-30
CVE-2026-81433 disclosed
A stack-based buffer overflow in the DHCP fingerprinting daemon of Fireware OS was disclosed, allowing code execution or crashes.
psirt.watchguard.com
2026-09-30
CVE-2026-18145 disclosed
A stack-based buffer overflow in the spamBlocker service of Fireware OS was disclosed, enabling potential code execution.
Psirt.Watchguard

More articles in this cluster (3)

Following this threat?

Track WatchGuard in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What systems are affected?
The vulnerabilities affect WatchGuard Fireware OS, specifically the DHCP fingerprinting daemon and spamBlocker service.
Is there a patch available?
No patches have been mentioned in the articles, indicating that these vulnerabilities may still be unpatched.
What are the potential impacts of these vulnerabilities?
Both vulnerabilities could lead to service crashes or arbitrary code execution, posing significant risks to affected systems.