WatchGuard Fireware OS and Dimension: five criticals including unauth iked RCE (CVSS 9.3)
WatchGuard PSIRT published a cluster of advisories on 27 August 2026 covering Fireware OS (iked / epm) and WatchGuard Dimension. Five issues are rated 9.3 on the vendor page: iked heap overflow CVE-2026-19313, iked stack overflow CVE-2026-19318 and iked type confusion CVE-2026-19315 (unauthenticated remote code execution via crafted traffic); epm stack overflow CVE-2026-13086 in the deprecated Mobile Security feature; and Dimension CVE-2026-78174, session-ID and CSRF token exposure that can let a low-privileged administrator take over a super-admin session. SecurityWeek (Ionut Arghire, 1 September) matches those five at CVSS 9.3. Patch to Fireware OS 2026.2.2, 12.12.2 or 12.5.20 and Dimension 2.3.1. WatchGuard also shipped additional high- and medium-severity fixes in the same wave (iked denial-of-service and Dimension SQL injection, CSRF, SSRF and related issues among them); this card does not list every CVE. The vendor is not aware of exploitation of these defects.
- Product
- WatchGuard Fireware OS (iked / epm) and WatchGuard Dimension
- Versions
- Fireware OS before 2026.2.2 / 12.12.2 / 12.5.20; Dimension before 2.3.1
- CVSS
- (CVSS 4.0, WatchGuard CNA; five criticals)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - Exploited in Australia?
- unknown
- Patch to
- Fireware OS 2026.2.2 / 12.12.2 / 12.5.20; Dimension 2.3.1
Primary: WatchGuard PSIRT advisories (27 Aug 2026) · Vendor: WatchGuard PSIRT · CVE: CVE-2026-19313, CVE-2026-19318, CVE-2026-19315, CVE-2026-13086, CVE-2026-78174 · SecurityWeek (1 Sep 2026)
