Description
WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server.

This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
Published: 2026-07-02
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a race condition that leads to a use‑after‑free in the LDAP authentication path used by the Mobile User VPN with IKEv2 on WatchGuard Fireware OS. An attacker that can trigger the flaw could execute arbitrary code as the iked process, effectively taking control over the Firebox. The flaw is classified as CWE‑416 and poses a high‑severity code‑execution risk that could compromise device integrity and availability.

Affected Systems

Affected system information is limited to Fireware OS releases 11.0 through 11.12.4_Update1, 12.0 through 12.12, and 2025.1 through 2026.2. Only devices that have Mobile VPN with IKEv2 configured to use an external LDAP authentication server are exposed; firmware versions newer than those or configurations without this feature are not vulnerable.

Risk and Exploitability

CVSS 9.2 indicates critical severity. EPSS less than 1% indicates a low current exploitation probability, but the remote, unauthenticated nature of the attack means an adversary could trigger the flaw by accessing the VPN and interacting with the LDAP authentication handshake. The exact mechanism of sending crafted LDAP messages is inferred from the description because the CVE text does not explicitly describe the attack vector; it only states a use‑after‑free that can lead to code execution. The vulnerability is not catalogued in CISA KEV, but its high severity and potential for full device takeover make it a top priority for mitigations.

Generated by OpenCVE AI on July 21, 2026 at 10:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest WatchGuard Fireware OS firmware that contains the fix for the race condition and use‑after‑free flaw
  • If an immediate firmware upgrade cannot be performed, disable Mobile VPN with IKEv2 LDAP authentication or restrict it to trusted internal IP ranges and block LDAP traffic from untrusted networks
  • Enable detailed logging of LDAP authentication events and monitor for anomalies, isolating vulnerable VPN endpoints using segmentation or firewall rules until the permanent patch is applied

Generated by OpenCVE AI on July 21, 2026 at 10:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
Title WatchGuard Firebox Race Condition and Use-After-Free in Mobile VPN with IKEv2 LDAP Authentication
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-416
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:11.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-07-07T03:56:35.031Z

Reserved: 2026-06-25T19:00:06.688Z

Link: CVE-2026-13368

cve-icon Vulnrichment

Updated: 2026-07-06T14:50:23.252Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:45:02Z

Weaknesses