NCSC-2026-0335 [1.00] [M/H] Vulnerabilities fixed in WatchGuard Fireware OS
WatchGuard has fixed vulnerabilities in WatchGuard Fireware OS, specifically in the iked process and epm service of the Mobile Security component. The vulnerabilities are located in the iked process and epm service of WatchGuard Fireware OS. The iked process contains a stack-based buffer overflow, a type confusion vulnerability, and a heap overflow. These vulnerabilities can be exploited by an unauthenticated attacker by sending specially crafted network traffic. This can lead to the execution of arbitrary code with the privileges of the iked process, potentially enabling complete control over the system. Additionally, the epm service, which is part of the obsolete Mobile Security component, contains a stack-based buffer overflow. This vulnerability can also be exploited by an unauthenticated attacker to execute arbitrary code and gain control over the system.
CSIRTS triage
- What
- Stack-based buffer overflow, type confusion, and heap overflow vulnerabilities exist in the iked process and epm service of the Mobile Security component.
- Who is affected
- Unauthenticated attackers can exploit these vulnerabilities in WatchGuard Fireware OS deployments with the Mobile Security component enabled.
- Urgency
- High urgency; unauthenticated remote code execution with system-level privileges is possible without any exploitation barriers.
- Action
- Update WatchGuard Fireware OS to the patched version addressing CVE-2026-13086, CVE-2026-19313, CVE-2026-19315, and CVE-2026-19318.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Fireware OS
Get an email when a new Fireware OS advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0335
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-130860.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-193130.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-193150.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-193180.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-13086 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19313 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19315 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19318 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] WatchGuard Firebox OS: Multiple vulnerabilitiescert-bund
- unknownCVE-2026-19318: A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows …nvd
- unknownCVE-2026-19315: A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote u…nvd
- unknownCVE-2026-19313: An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unau…nvd
- unknownCVE-2026-13086: A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the dep…nvd
Recent advisories for WatchGuard Fireware OS
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-78011: An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote …nvd · 2026-08-28
- unknownCVE-2026-78010: A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process iallows…nvd · 2026-08-28
- unknownCVE-2026-78009: An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote…nvd · 2026-08-28
- unknownCVE-2026-78008: A buffer overflow vulnerability in the WatchGuard Fireware OS Management Web UI allows an auth…nvd · 2026-08-28
- unknownCVE-2026-19318: A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows …nvd · 2026-08-28
- unknownCVE-2026-19317: An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote…nvd · 2026-08-28
More from NCSC-NL Advisories
- unknownNCSC-2026-0337 [1.00] [H/H] Zero-Day vulnerabilities patched in SonicWall SMA1000 Appliance2026-09-02
- unknownNCSC-2026-0336 [1.00] [M/H] Vulnerability patched in JFrog Artifactory2026-09-02
- unknownNCSC-2026-0334 [1.00] [M/H] Vulnerabilities patched in PaperCut MF and PaperCut NG from PaperCut2026-08-28
- unknownNCSC-2026-0289 [1.01] [H/H] Vulnerabilities patched in Microsoft Exchange Server2026-08-28
- unknownNCSC-2026-0333 [1.00] [M/H] Vulnerabilities patched in CodeMeter Runtime from Wibu-Systems2026-08-28