WatchGuard Patches Critical Vulnerabilities
WatchGuard has released patches for over two dozen vulnerabilities, including five critical flaws that could lead to remote code execution and account takeover. These vulnerabilities primarily affect their Fireware OS and Dimension security products. The company states it’s not currently aware of active exploitation, but urges users to update immediately.
WatchGuard has released patches to address a significant number of security vulnerabilities across its Fireware OS and Dimension security products. The vulnerabilities include five critical flaws that could allow attackers to execute code remotely and take over user accounts. Specifically, three critical bugs within Fireware OS’s iked process – a core component for handling cryptographic key establishment and IPsec VPN negotiations – are a heap buffer overflow (CVE-2026-19313), a stack-based buffer overflow (CVE-2026-19318), and a type confusion (CVE-2026-19315). Attackers could exploit these issues by sending crafted network traffic to trigger the vulnerabilities and achieve remote code execution.
Another critical stack-based buffer overflow bug (CVE-2026-13086) was found in the Endpoint Protection Manager (epm) service, previously used in the deprecated Mobile Security feature of Fireware OS. This could also lead to remote code execution. Furthermore, CVE-2026-78174 in WatchGuard Dimension could allow low-privileged administrators to extract a super admin’s session ID and CSRF tokens, enabling account takeover.
All five critical vulnerabilities have a CVSS score of 9.3. The patches are included in Fireware OS versions 2026.2.2, 12.12.2, and 12.5.20, and Dimension version 2.3.1. In addition to these, the company fixed seven high-severity Fireware OS vulnerabilities that could lead to denial-of-service (DoS), and five high-severity Dimension bugs leading to arbitrary command execution, tampering with the global administrator’s passphrase, and DoS. Finally, 11 medium-severity vulnerabilities were addressed, including one in Fireware OS’s iked process and 10 in Dimension. WatchGuard states it is not currently aware of any of these security defects being exploited in the wild, but recommends immediate updates.