Description
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.
Published: 2026-07-02
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write flaw exists in the ikestubd daemon of WatchGuard Fireware OS. The vulnerability can be triggered by a specially crafted request sent to the Management Web UI. When executed, the memory corruption allows an attacker to run arbitrary code on the device with the privileges of the ikestubd process. The risk to confidentiality, integrity, and availability is classified as high, reflected by a CVSS score of 8.6.

Affected Systems

Fireware OS releases 12.1 through 12.12 and 2025.1 through 2026.2 are affected. Devices running these versions expose the Management Web UI and run the ikestubd process to provide infrastructure services.

Risk and Exploitability

Exploitation requires an authenticated privileged user with access to the Management Web UI; the flaw is not remotely exploitable by unauthenticated users. The EPSS score is less than 1%, implying a low but measurable exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, so no public exploits are known. If an attacker successfully authenticates with elevated privileges, they could achieve arbitrary code execution on the device.

Generated by OpenCVE AI on July 21, 2026 at 10:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest WatchGuard firmware update that includes the ikestubd patch
  • Restrict privileged accounts that can access the Management Web UI
  • Enforce multi‑factor authentication for all privileged UI access
  • Limit or disable the Management Web UI to trusted IP ranges or a dedicated management network

Generated by OpenCVE AI on July 21, 2026 at 10:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.
Title WatchGuard Firebox ikestubd Out of Bounds Write Vulnerability
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-787
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-07-07T03:56:38.252Z

Reserved: 2026-06-25T22:44:09.033Z

Link: CVE-2026-13383

cve-icon Vulnrichment

Updated: 2026-07-06T14:32:03.370Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:45:02Z

Weaknesses