CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0335 [1.00] [M/H] Vulnerabilities fixed in WatchGuard Fireware OS

unknownCVE-2026-13086CVE-2026-19313CVE-2026-19315CVE-2026-19318
WatchGuard has fixed vulnerabilities in WatchGuard Fireware OS, specifically in the iked process and epm service of the Mobile Security component. The vulnerabilities are located in the iked process and epm service of WatchGuard Fireware OS. The iked process contains a stack-based buffer overflow, a type confusion vulnerability, and a heap overflow. These vulnerabilities can be exploited by an unauthenticated attacker by sending specially crafted network traffic. This can lead to the execution of arbitrary code with the privileges of the iked process, potentially enabling complete control over the system. Additionally, the epm service, which is part of the obsolete Mobile Security component, contains a stack-based buffer overflow. This vulnerability can also be exploited by an unauthenticated attacker to execute arbitrary code and gain control over the system.

CSIRTS triage

What
Stack-based buffer overflow, type confusion, and heap overflow vulnerabilities exist in the iked process and epm service of the Mobile Security component.
Who is affected
Unauthenticated attackers can exploit these vulnerabilities in WatchGuard Fireware OS deployments with the Mobile Security component enabled.
Urgency
High urgency; unauthenticated remote code execution with system-level privileges is possible without any exploitation barriers.
Action
Update WatchGuard Fireware OS to the patched version addressing CVE-2026-13086, CVE-2026-19313, CVE-2026-19315, and CVE-2026-19318.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Fireware OS

Get an email when a new Fireware OS advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-09-01
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0335

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-13086coverage & exploitation statusNVD · CVE.org
CVE-2026-19313coverage & exploitation statusNVD · CVE.org
CVE-2026-19315coverage & exploitation statusNVD · CVE.org
CVE-2026-19318coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for WatchGuard Fireware OS

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories