CVE-2026-19315CWE-125CWE-763CWE-843

CVE-2026-19315

published August 28, 2026

CVSS
9.3
EPSS
0%
Percentile
38.2
In the wild
Unconfirmed
What it is

A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

The record
Technical detail
CVSS
9.3 · NONE
CVSS v4.0
9.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00457 · 38.2th percentile
Weaknesses
CWE-125 · Out-of-bounds Read; CWE-763 · Release of Invalid Pointer or Reference; CWE-843 · Access of Resource Using Incompatible Type ('Type Confusion')
Published
2026-08-28T06:16Z
References (1)
EPSS history
Timeline
  • 27 AUG 23:24Z
    Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code Execution
    cvelistv5