Impact
WatchGuard Fireware OS contains a race condition that results in a use‑after‑free vulnerability within the LDAP authentication flow for Mobile User VPN with IKEv2. An unauthenticated attacker can trigger the flaw by interacting with the VPN and its LDAP handshake, causing arbitrary code to run in the context of the iked process. This permits full control over the affected Firebox, compromising confidentiality, integrity, and availability of the device.
Affected Systems
The flaw affects WatchGuard Fireware OS devices that have Mobile VPN with IKEv2 enabled and are configured to use an external LDAP authentication server. The vendor lists Fireware OS 2026.2.1, 12.12.1, and 12.5.19 as the firmware releases that contain the fix.
Risk and Exploitability
The CVSS score of 9.2 indicates critical severity, yet the EPSS score of less than 1% signals a very low probability of exploitation. The vulnerability is not included in the CISA KEV catalog. Because the flaw is exploitable remotely and allows arbitrary code execution, it remains a top‑priority target for remediation.
OpenCVE Enrichment