CVE-2026-19315 – Watchguard Fireware OS

CVSS 9.3 CRITICAL Critical - Same Day Deployment

“Three pre-authentication flaws put exposed Fireboxes at risk of full remote compromise.”

WatchGuard fixed three critical vulnerabilities in the Fireware OS iked process. CVE-2026-19313 is a heap overflow, CVE-2026-19318 is a stack-based buffer overflow, and CVE-2026-19315 is a type confusion flaw. Each can allow a remote, unauthenticated attacker to execute arbitrary code using specially crafted network traffic. Each CVE has a CVSS score of 9.3, Critical severity.

The fixes are included in Fireware OS 2026.2.2, 12.12.2, and 12.5.20 for applicable systems.

Key Details

CWE Classification
CWE-125
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.