September 4, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-13368NVD

Vulnerability Summary

WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server.
Severity Level
CRITICAL(9.2)
Published Date
Jul 2, 2026
Last Modified
Aug 27, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
1.01%Probability
Root Weakness (CWE)
N/A
CVSS v4.0 Base Metrics