CVE-2026-19317
published 2026-08-28CVE-2026-19317: An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS)…
PriorityP354high8.7CVSS 4.0
AVNACLATNPRNUINVCNVINVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.32%
25.4th percentile
An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| watchguard | fireware_os | >= 12.0 < 12.12.2 | 12.12.2 |
| watchguard | fireware_os | >= 12.0 < 12.5.20 | 12.5.20 |
| watchguard | fireware_os | >= 2025.0 < 2026.2.2 | 2026.2.2 |
| watchguard | fireware_os | >= 2026.3 < 2026.3.1 | 2026.3.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WatchGuard Fireware OS iked denial of service (EUVD-2026-67337 / WID-SEC-2026-3068)
vuldb·2026-09-04·CVSS 8.7
CVE-2026-19317 [HIGH] WatchGuard Fireware OS iked denial of service (EUVD-2026-67337 / WID-SEC-2026-3068)
A vulnerability marked as critical has been reported in WatchGuard Fireware OS. Affected by this issue is some unknown functionality of the component iked. This manipulation causes denial of service.
This vulnerability appears as CVE-2026-19317. The attack may be initiated remotely. There is no available exploit.
GHSA
An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending speci
ghsa_unreviewed·2026-08-28
CVE-2026-19317 [HIGH] CWE-125 An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending speci
An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-28
Published