CVE-2026-18105
published 2026-09-30CVE-2026-18105: An uncontrolled resource consumption vulnerability in Fireware OS's diagnostic tasks feature allows a low-privileged, authenticated user to cause a denial of…
PriorityP336high7.1CVSS 4.0
AVNACLATNPRLUINVCNVINVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.23%
12.1th percentile
An uncontrolled resource consumption vulnerability in Fireware OS's diagnostic tasks feature allows a low-privileged, authenticated user to cause a denial of service of the system's diagnostic tools by repeatedly starting and aborting a specially crafted diagnostic task through the web UI.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| watchguard | fireware_os | >= 12.0 < 12.12.3 | 12.12.3 |
| watchguard | fireware_os | >= 12.0 < 12.5.21 | 12.5.21 |
| watchguard | fireware_os | >= 2025.0 < 2026.2.3 | 2026.2.3 |
| watchguard | fireware_os | >= 2026.3 < 2026.3.2 | 2026.3.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WatchGuard Fireware OS Diagnostic Tasks resource consumption
vuldb·2026-09-30·CVSS 7.1
CVE-2026-18105 [HIGH] WatchGuard Fireware OS Diagnostic Tasks resource consumption
A vulnerability has been found in WatchGuard Fireware OS and classified as critical. This impacts an unknown function of the component Diagnostic Tasks. The manipulation leads to resource consumption.
This vulnerability is uniquely identified as CVE-2026-18105. The attack is possible to be carried out remotely. No exploit exists.
GHSA
An uncontrolled resource consumption vulnerability in Fireware OS's diagnostic tasks feature allows a low-privileged, authenticated user to cause a denial of service of the system's diagnostic tools b
ghsa_unreviewed·2026-09-30
CVE-2026-18105 [HIGH] CWE-400 An uncontrolled resource consumption vulnerability in Fireware OS's diagnostic tasks feature allows a low-privileged, authenticated user to cause a denial of service of the system's diagnostic tools b
An uncontrolled resource consumption vulnerability in Fireware OS's diagnostic tasks feature allows a low-privileged, authenticated user to cause a denial of service of the system's diagnostic tools by repeatedly starting and aborting a specially crafted diagnostic task through the web UI.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-30
Published