Description
A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process iallows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
Published: 2026-08-27
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack-based buffer overflow in the iked process of WatchGuard Fireware OS allows a remote attacker, without authentication, to send crafted traffic that overflows a buffer and causes the VPN component to crash, resulting in a denial of service. This failure is a classic stack overflow (CWE-121) that could potentially lead to memory corruption and skipped processes (CWE-787).

Affected Systems

The vulnerability affects all versions of WatchGuard Fireware OS prior to the listed patch releases. The official fix is available in Fireware OS 2026.2.2, Fireware OS 12.12.2, and Fireware OS 12.5.20. Any installation of these earlier versions is susceptible to the flaw.

Risk and Exploitability

The CVSS score of 8.7 classifies this issue as high severity. The exploit requires no authentication and is delivered via specially crafted network traffic directed at the iked service, making it remotely exploitable from the Internet. With no exploit probability score reported and the vulnerability not listed in the CISA KEV catalog, the threat is significant but the likelihood of an immediate exploited attack remains uncertain. Nonetheless, the combination of a high CVSS score and remote unauthenticated trigger warrants prompt action.

Generated by OpenCVE AI on August 28, 2026 at 07:34 UTC.

Remediation

Vendor Solution

Fireware OS 2026.2.2, Fireware OS 12.12.2, Fireware OS 12.5.20


OpenCVE Recommended Actions

  • Upgrade WatchGuard Fireware OS to the patched versions 2026.2.2, 12.12.2, or 12.5.20, depending on the deployment.
  • If an immediate upgrade is not possible, block inbound VPN service traffic to the iked process using firewall rules or network segmentation to limit exposure.
  • Apply general best practices for stack protection, such as enabling stack canaries and address space layout randomization, to mitigate similar vulnerabilities until a full patch is deployed.

Generated by OpenCVE AI on August 28, 2026 at 07:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process iallows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
Title Fireware OS Stack-Based Buffer Overflow in iked Allows Unauthenticated Denial of Service
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-121
CWE-1284
CWE-787
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-27T23:24:32.821Z

Reserved: 2026-08-21T21:46:45.307Z

Link: CVE-2026-78010

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T02:16:22.417

Modified: 2026-08-28T02:16:22.417

Link: CVE-2026-78010

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T07:45:04Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow

  • CWE-1284

    Improper Validation of Specified Quantity in Input

  • CWE-787

    Out-of-bounds Write