Skip to content

WatchGuard Technologies Fireware OS: stack buffer overflow

High8.6CVE-2026-18145 · Published Sep 30, 2026 · updated Oct 1, 2026

A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending a specially crafted management request.

Affected versions

PackageAffectedFixed in
Fireware OS
Product
>= 2026.3, < 2026.3.22026.3.2
>= 2025.0, < 2026.2.32026.2.3
>= 12.0, < 12.12.312.12.3
>= 12.0, < 12.5.2112.5.21
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-121

More WatchGuard Technologies advisories

All WatchGuard Technologies
Advisory
WatchGuard Technologies Fireware OS: null pointer dereference
High8.7Sep 30
WatchGuard Technologies Fireware OS: integer overflow
High8.2Sep 30
WatchGuard Technologies Fireware OS: missing authorization
High7.1Sep 30
WatchGuard Technologies Fireware OS: missing authorization
High7.1Sep 30
WatchGuard Technologies Fireware OS: stack buffer overflow
High8.7Sep 30
WatchGuard Technologies Fireware OS: improper authorization
High7.2Sep 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.