Description
WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server.
Published: 2026-07-02
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WatchGuard Fireware OS contains a race condition that results in a use‑after‑free vulnerability within the LDAP authentication flow for Mobile User VPN with IKEv2. An unauthenticated attacker can trigger the flaw by interacting with the VPN and its LDAP handshake, causing arbitrary code to run in the context of the iked process. This permits full control over the affected Firebox, compromising confidentiality, integrity, and availability of the device.

Affected Systems

The flaw affects WatchGuard Fireware OS devices that have Mobile VPN with IKEv2 enabled and are configured to use an external LDAP authentication server. The vendor lists Fireware OS 2026.2.1, 12.12.1, and 12.5.19 as the firmware releases that contain the fix.

Risk and Exploitability

The CVSS score of 9.2 indicates critical severity, yet the EPSS score of less than 1% signals a very low probability of exploitation. The vulnerability is not included in the CISA KEV catalog. Because the flaw is exploitable remotely and allows arbitrary code execution, it remains a top‑priority target for remediation.

Generated by OpenCVE AI on August 10, 2026 at 23:10 UTC.

Remediation

Vendor Solution

Fireware OS 2026.2.1, Fireware OS 12.12.1, Fireware OS 12.5.19


OpenCVE Recommended Actions

  • Upgrade the device to a firmware version that includes the fix (Fireware OS 2026.2.1, 12.12.1, or 12.5.19).
  • If an update cannot be applied immediately, disable Mobile VPN with IKEv2 LDAP authentication or limit its use to a trusted internal network segment and block LDAP traffic from external sources.
  • Enable detailed logging of LDAP authentication events and monitor the logs for anomalies; place affected Fireboxes behind network segmentation or additional firewall rules until the patch is applied.

Generated by OpenCVE AI on August 10, 2026 at 23:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2. WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server.
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:11.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*
References

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
Title WatchGuard Firebox Race Condition and Use-After-Free in Mobile VPN with IKEv2 LDAP Authentication
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-416
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:11.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-10T17:50:19.133Z

Reserved: 2026-06-25T19:00:06.688Z

Link: CVE-2026-13368

cve-icon Vulnrichment

Updated: 2026-07-06T14:50:23.252Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-03T00:16:50.890

Modified: 2026-08-10T18:17:39.720

Link: CVE-2026-13368

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T23:15:05Z

Weaknesses