WatchGuard TechnologiesCVE-2026-19316
WatchGuard Technologies Fireware OS: denial of service
High8.7CVE-2026-19316 · Published Aug 28, 2026 · updated Sep 3, 2026
A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Fireware OS Product | >= 2025.0, < 2026.2.2 | 2026.2.2 |
| >= 12.0, < 12.12.2 | 12.12.2 | |
| >= 2026.3, < 2026.3.1 | 2026.3.1 | |
| >= 12.0, < 12.5.20 | 12.5.20 |
Details and references
More WatchGuard Technologies advisories
All WatchGuard Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 28 | WatchGuard Technologies Dimension: SQL injection | High8.6 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: cross-site scripting | Medium4.6 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: cross-site scripting | Medium4.8 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: observable discrepancy | Medium6.3 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: improper access control | Medium6.9 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: server-side request forgery | Medium5.3 | 2.3.1 |