Stack-Based Buffer Overflow Vulnerabilities in WatchGuard Fireware OS
Article Content
- •CVE-2026-81433 allows unauthenticated adjacent network access exploitation.
- •CVE-2026-18145 requires authenticated admin privileges for exploitation.
- •Both vulnerabilities could lead to service crashes or arbitrary code execution.
Two stack-based buffer overflow vulnerabilities have been identified in WatchGuard Fireware OS. CVE-2026-81433 affects the DHCP fingerprinting daemon, allowing unauthenticated attackers with adjacent network access to execute arbitrary code or crash the process through specially crafted DHCP packets. CVE-2026-18145 impacts the spamBlocker service, permitting authenticated attackers with admin privileges to crash the service or execute arbitrary code via crafted management requests. Both vulnerabilities pose significant risks to users of WatchGuard Fireware OS. The vulnerabilities have been disclosed today, and further details are available on the CVE database. No patches have been mentioned in the articles, indicating that these vulnerabilities may still be.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track WatchGuard in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What systems are affected?
Is there a patch available?
What are the potential impacts of these vulnerabilities?
Continue Reading
Microsoft September 2026 Patch Tuesday: Record 974 Vulnerabilities Addressed On September 8, 2026, Microsoft released a record-breaking 974 patches for vulnerabilities across its products, including two actively exploited zero-day vulnerabilities: CVE-2026-81963 and CVE-2026-85880. These vulnerabilities allow local attackers to escalate privileges to SYSTEM level, posing significant risks to…
High-Risk OS Command Injection Vulnerability in PLANET IGS-5225 Switches PLANET Technology Corp. has disclosed a critical OS command injection vulnerability (CVE-2026-81942) affecting the IGS-5225-8P2T4S industrial managed switch firmware versions prior to 1.2412b260707 and 2.2412b260519. This vulnerability allows remote authenticated attackers to execute arbitrary commands on the…