TL;DR
WatchGuard patched five critical flaws in Fireware OS and Dimension on August 27, 2026. Each carries a CVSS score of 9.3. The most serious WatchGuard Fireware vulnerability allows pre-authentication remote code execution on internet-facing firewalls.
- Total: 5 CVEs
- Severity: 5 Critical
- Actively exploited: None confirmed
- Highest severity: 9.3 (Critical · CVSSv4) — CVE-2026-19313
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-19313 | 9.3 | Pre-Authentication Heap Buffer Overflow in iked Allows Remote Code Execution | 2026.2.2, 12.12.2, 12.5.20 | Not exploited |
| CVE-2026-19318 | 9.3 | Pre-Authentication Stack Buffer Overflow in iked Allows Remote Code Execution | 2026.2.2, 12.12.2, 12.5.20 | Not exploited |
| CVE-2026-19315 | 9.3 | Pre-Authentication Type Confusion in iked Allows Remote Code Execution | 2026.2.2, 12.12.2, 12.5.20 | Not exploited |
| CVE-2026-13086 | 9.3 | Stack-Based Buffer Overflow in Mobile Security epm Endpoint | 2026.2.2, 12.12.2, 12.5.20 | Not exploited |
| CVE-2026-78174 | 9.3 | Session Hijack via Exposed Session Tokens in Diagnostic Logs | 2.3.1 | Not exploited |
Why It Matters
Firewalls sit at the network edge. A pre-auth flaw there gives attackers a direct path inside. Three of these bugs live in the IKE daemon (iked), which handles VPN traffic. That service often faces the public internet. A single WatchGuard Fireware vulnerability in that path is a prime ransomware target.
How the Attack Works
The iked bugs share a pattern. A remote, unauthenticated attacker sends crafted network traffic to the VPN service. CVE-2026-19313 triggers a heap buffer overflow. CVE-2026-19318 is a stack overflow reached through a malformed EAP-MSCHAPv2 payload. CVE-2026-19315 is a type confusion bug that frees an attacker-influenced pointer. Each can crash the daemon and open the door to code execution. Separately, CVE-2026-13086 hits the deprecated Mobile Security epm service. It runs code as root with “no stack canary” and a non-PIE binary. CVE-2026-78174 affects WatchGuard Dimension. There, a low-privileged admin can steal a Super Administrator session token from a diagnostic log. No exploit code appears here.
Affected Versions
The Fireware flaws affect default builds from 2025.0 up to 2026.2.2, and 12.0 up to 12.12.2. T15 and T35 models are affected below 12.5.20. The Dimension bug affects versions 2.0 up to 2.3.1.
Patch and Mitigation
Update now. WatchGuard fixed Fireware in 2026.2.2, 12.12.2, and 12.5.20. Dimension is patched in 2.3.1. Details and full product tables sit in the official WatchGuard PSIRT advisories. Where patching lags, restrict management and VPN access to trusted networks.
Exploitation Status
WatchGuard reports no exploitation in the wild for any of these flaws. No public proof-of-concept has been confirmed.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!