Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026090708092525 | Publication Time | 2026-09-07 08:58:25 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-09-07 08:58:25 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】WatchGuard Fireware OS iked Contains Three Critical Cybersecurity Vulnerabilities |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000005 WatchGuard issued critical cybersecurity vulnerability advisories for its Fireware OS iked (CVE-2026-19313, CVE-2026-19315, and CVE-2026-19318), all of which have a CVSS 4.x score of 9.3. CVE-2026-19313 is a Heap Overflow vulnerability that allows an unauthenticated remote attacker to execute arbitrary code through specially crafted network traffic. CVE-2026-19315 is a Type Confusion vulnerability that allows an unauthenticated remote attacker to trigger memory handling errors through specially crafted network packets, potentially leading to arbitrary code execution. CVE-2026-19318 is a Stack-based Buffer Overflow vulnerability that allows an unauthenticated remote attacker to execute arbitrary code through specially crafted network packets. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
Default - Fireware OS versions 2025.0 to versions prior to 2026.2.2 |
|||
|
[Recommended Actions] Please update to the following versions: 【CVE-2026-19313, CVE-2026-19318】Default - Fireware OS version 2026.2.2 or later, Default - Fireware OS version 12.12.2 or later, T15/T35 - Fireware OS version 12.5.20 or later, T15/T35 - Fireware OS version 2026.3.1 or later 【CVE-2026-19315】Default - Fireware OS version 2026.2.2 or later, Default - Fireware OS version 12.12.2 or later, Default - Fireware OS version 2026.3.1 or later, T15/T35 - Fireware OS version 12.5.20 or later |
|||
|
[Reference] |
|||