483/69 Thursday, September 3, 2026

WatchGuard has released patches to address more than 20 vulnerabilities in Fireware OS and WatchGuard Dimension, including five Critical vulnerabilities that could lead to remote code execution (RCE) or administrator account takeover. The five Critical vulnerabilities have CVSS scores of 9.3 and have been fixed in Fireware OS versions 2026.2.2, 12.12.2, and 12.5.20, as well as WatchGuard Dimension version 2.3.1.
The three Critical vulnerabilities in Fireware OS are CVE-2026-19313, CVE-2026-19318, and CVE-2026-19315. They affect the iked process, which handles Internet Key Exchange and IPsec VPN negotiation through IKEv1 and IKEv2. An unauthenticated attacker could send specially crafted network traffic to trigger a heap buffer overflow, stack-based buffer overflow, or type confusion issue, potentially leading to remote code execution. Another Critical vulnerability, CVE-2026-13086, is a stack-based buffer overflow in the Endpoint Protection Manager service, or epm, related to the deprecated Mobile Security feature, and could also lead to RCE.
The remaining Critical vulnerability is CVE-2026-78174 in WatchGuard Dimension, which could allow a low-privileged administrator to retrieve the session ID and CSRF token of a Super Admin account from diagnostic logs, potentially leading to account takeover. WatchGuard stated that it has not observed these vulnerabilities being exploited in attacks. Administrators should check the versions in use and update Fireware OS to version 2026.2.2, 12.12.2, or 12.5.20, depending on the device model, and update WatchGuard Dimension to version 2.3.1. They should also restrict access to management systems to only necessary users and review logs for abnormal activity.
Source: https://www.securityweek.com/watchguard-patches-critical-vulnerabilities/
