Description
An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
Published: 2026-08-27
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer underflow in the iked process of WatchGuard Fireware OS allows an attacker to send crafted packets that interrupt VPN handling, causing the firewall to become unresponsive. The flaw can be triggered without authentication and results in a denial of service that affects the availability of the VPN service and potentially the entire network segmentation function of the device.

Affected Systems

The vulnerability exists in all supported releases of WatchGuard Fireware OS up to the officially released updates. Devices running versions before Fireware OS 2026.2.2, 12.12.2, or 12.5.20 are susceptible. Any organization using WatchGuard Fireware OS for VPN connectivity should verify that its firmware matches one of the patched releases.

Risk and Exploitability

The CVSS base score of 8.7 indicates high exploitation potential, though the EPSS score is not reported and the vulnerability is not listed in the CISA KEV catalog. Because the attack can be performed remotely without authentication, the risk to network availability is significant. Patch application is the primary mitigation to remove the Integer Underflow and associated Out‑of‑Bounds Write weaknesses identified as CWE‑191 and CWE‑787.

Generated by OpenCVE AI on August 28, 2026 at 07:33 UTC.

Remediation

Vendor Solution

Fireware OS 2026.2.2, Fireware OS 12.12.2, Fireware OS 12.5.20


OpenCVE Recommended Actions

  • Upgrade the device to Fireware OS 2026.2.2, 12.12.2, or 12.5.20, depending on the build in use.
  • Restart the iked service or reboot the firewall to ensure the updated code is active.
  • Verify that VPN functionality resumes normally and monitor logs for unexpected service restarts or DoS attempts.

Generated by OpenCVE AI on August 28, 2026 at 07:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
Title Fireware OS Integer Underflow in Iked Allows Unauthenticated Denial of Service (DoS)
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-191
CWE-787
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-27T23:24:33.126Z

Reserved: 2026-08-21T21:46:48.681Z

Link: CVE-2026-78011

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T02:16:22.563

Modified: 2026-08-28T02:16:22.563

Link: CVE-2026-78011

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T07:45:04Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)

  • CWE-787

    Out-of-bounds Write