WatchGuard released fixes for five critical vulnerabilities in Fireware OS and WatchGuard Dimension, all rated CVSS v4 9.3. Three flaws in the internet-exposed iked IKE/VPN daemon—including the pre-authentication stack buffer overflow tracked as CVE-2026-19318—could allow unauthenticated attackers to execute code by sending crafted VPN traffic, creating a direct perimeter-compromise risk.
A fourth Fireware issue affects the deprecated Mobile Security epm service, while a WatchGuard Dimension vulnerability could let a low-privileged administrator hijack a Super Administrator session. WatchGuard reported no confirmed exploitation or public proof-of-concept code, but organizations should apply the available updates immediately; where patching is delayed, VPN and management interfaces should be limited to trusted networks.

Map this exposure pattern across your cloud, code, and identities.
1 event from the most recent confirmed update back to the earliest known activity.
WatchGuard released updates for five critical vulnerabilities, including three pre-authentication remote-code-execution flaws in the Fireware iked VPN service, an epm service buffer overflow, and a WatchGuard Dimension session-token exposure issue. The vendor identified Fireware 2026.2.2, 12.12.2, and 12.5.20, and Dimension 2.3.1, as fixed versions, and reported no confirmed exploitation or public proof-of-concept code.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
3 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourcesecurityonline.info
Open sourcepsirt.watchguard.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.