CVE-2026-19313CWE-122CWE-190CWE-680

CVE-2026-19313

published August 28, 2026

CVSS
9.3
EPSS
0%
Percentile
39.1
In the wild
Unconfirmed
What it is

An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

The record
Technical detail
CVSS
9.3 · NONE
CVSS v4.0
9.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00471 · 39.1th percentile
Weaknesses
CWE-122 · Heap-based Buffer Overflow; CWE-190 · Integer Overflow or Wraparound; CWE-680 · Integer Overflow to Buffer Overflow
Published
2026-08-28T06:16Z
References (1)
EPSS history
Timeline
  • 27 AUG 23:24Z
    Fireware OS Pre-Authentication Heap Buffer Overflow in iked Allows Remote Code Execution
    cvelistv5