Jump to the main content block

【Vulnerability Alert】WatchGuard Fireware OS iked Contains Three Critical Cybersecurity Vulnerabilities

publish date : 2026-09-11 update date : 2026-09-11

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026090708092525 Publication Time 2026-09-07 08:58:25
Incident Type ANA-Vulnerability Alert Discovery Time 2026-09-07 08:58:25
Impact Level Low  
[Subject]
【Vulnerability Alert】WatchGuard Fireware OS iked Contains Three Critical Cybersecurity Vulnerabilities
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000005

WatchGuard issued critical cybersecurity vulnerability advisories for its Fireware OS iked (CVE-2026-19313, CVE-2026-19315, and CVE-2026-19318), all of which have a CVSS 4.x score of 9.3.

CVE-2026-19313 is a Heap Overflow vulnerability that allows an unauthenticated remote attacker to execute arbitrary code through specially crafted network traffic.

CVE-2026-19315 is a Type Confusion vulnerability that allows an unauthenticated remote attacker to trigger memory handling errors through specially crafted network packets, potentially leading to arbitrary code execution.

CVE-2026-19318 is a Stack-based Buffer Overflow vulnerability that allows an unauthenticated remote attacker to execute arbitrary code through specially crafted network packets.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

Default - Fireware OS versions 2025.0 to versions prior to 2026.2.2
Default - Fireware OS versions 12.0 to versions prior to 12.12.2
T15/T35 - Fireware OS versions 12.0 to versions prior to 12.5.20
T15/T35 - Fireware OS versions 2026.3 to versions prior to 2026.3.1
Default - Fireware OS versions 2026.3 to versions prior to 2026.3.1

[Recommended Actions]

Please update to the following versions:

【CVE-2026-19313, CVE-2026-19318】Default - Fireware OS version 2026.2.2 or later, Default - Fireware OS version 12.12.2 or later, T15/T35 - Fireware OS version 12.5.20 or later, T15/T35 - Fireware OS version 2026.3.1 or later

【CVE-2026-19315】Default - Fireware OS version 2026.2.2 or later, Default - Fireware OS version 12.12.2 or later, Default - Fireware OS version 2026.3.1 or later, T15/T35 - Fireware OS version 12.5.20 or later

[Reference]

 https://www.twcert.org.tw/tw/cp-169-11187-6a4cd-1.html

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center
Click Num: