Posting Date: 2026/09/07
【Vulnerability Alert】3 Critical Security Vulnerabilities Found in WatchGuard Fireware OS iked
- Subject: 【Vulnerability Alert】3 Critical Security Vulnerabilities Found in WatchGuard Fireware OS iked
- Description:
- Forwarded security alert TWCERTCC-200-202609-00000005 from Taiwan Computer Emergency Response Team/Coordination Center (TWCERT/CC).
- WatchGuard has issued a security alert regarding critical security vulnerabilities in Fireware OS iked (CVE-2026-19313, CVE-2026-19315, CVE-2026-19318), all with a CVSS 4.x score of 9.3.
- CVE-2026-19313: A heap-based buffer overflow vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code using specially crafted network traffic.
- CVE-2026-19315: A type confusion vulnerability that allows an unauthenticated, remote attacker to trigger memory handling errors using specially crafted network packets, potentially leading to arbitrary code execution.
- CVE-2026-19318: A stack-based buffer overflow vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code using specially crafted network packets.
- Affected Platforms:
- Default - Fireware OS 2025.0 to versions prior to 2026.2.2
- Default - Fireware OS 12.0 to versions prior to 12.12.2
- T15/T35 - Fireware OS 12.0 to versions prior to 12.5.20
- T15/T35 - Fireware OS 2026.3 to versions prior to 2026.3.1
- Default - Fireware OS 2026.3 to versions prior to 2026.3.1
- Recommendations:
- Please update to the following versions:
- 【CVE-2026-19313, CVE-2026-19318】 Default - Fireware OS version 2026.2.2 and subsequent versions, Default - Fireware OS version 12.12.2 and subsequent versions, T15/T35 - Fireware OS version 12.5.20 and subsequent versions, T15/T35 - Fireware OS version 2026.3.1 and subsequent versions
- 【CVE-2026-19315】 Default - Fireware OS version 2026.2.2 and subsequent versions, Default - Fireware OS version 12.12.2 and subsequent versions, Default - Fireware OS version 2026.3.1 and subsequent versions, T15/T35 - Fireware OS version 12.5.20 and subsequent versions
- References:
Computer and Communication Center
Network System Division