WatchGuard TechnologiesCVE-2026-18145
WatchGuard Technologies Fireware OS: stack buffer overflow
High8.6CVE-2026-18145 · Published Sep 30, 2026 · updated Oct 1, 2026
A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending a specially crafted management request.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Fireware OS Product | >= 2026.3, < 2026.3.2 | 2026.3.2 |
| >= 2025.0, < 2026.2.3 | 2026.2.3 | |
| >= 12.0, < 12.12.3 | 12.12.3 | |
| >= 12.0, < 12.5.21 | 12.5.21 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-121
More WatchGuard Technologies advisories
All WatchGuard Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 30 | WatchGuard Technologies Fireware OS: null pointer dereference | High8.7 | 2026.3.2+3 more |
| Sep 30 | WatchGuard Technologies Fireware OS: integer overflow | High8.2 | 2026.3.2+3 more |
| Sep 30 | WatchGuard Technologies Fireware OS: missing authorization | High7.1 | 2026.3.2+3 more |
| Sep 30 | WatchGuard Technologies Fireware OS: missing authorization | High7.1 | 2026.3.2+3 more |
| Sep 30 | WatchGuard Technologies Fireware OS: stack buffer overflow | High8.7 | 2026.3.2+2 more |
| Sep 30 | WatchGuard Technologies Fireware OS: improper authorization | High7.2 | 2026.3.2+3 more |