← Back to CVE List
Vulnerability Intelligence Report
Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code Execution

CVE-2026-19315

A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

No Active Exploit Signals
CVSS Base Score
9.3
CRITICAL
EPSS Probability:0.46%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

Affected Products & Versions

Vendor Product Affected Versions
WatchGuard Fireware OS 2025.0 < 2026.2.2 (affected), 12.0 < 12.12.2 (affected), 2026.3 < 2026.3.1 (affected)
WatchGuard Fireware OS 12.0 < 12.5.20 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.457%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityWatchGuard Technologies, Inc. · Vendor · USA
Reserved2026-08-07T20:05:56
Published2026-08-27T23:24:33
Patch Date2026-08-27
Last Updated2026-09-03T20:49:55

LINK COPIED TO CLIPBOARD