Vulnerability
Published 2026-08-27
Verified 2026-09-19

WatchGuard Fireware OS and Dimension: five criticals including unauth iked RCE (CVSS 9.3)

WatchGuard PSIRT published a cluster of advisories on 27 August 2026 covering Fireware OS (iked / epm) and WatchGuard Dimension. Five issues are rated 9.3 on the vendor page: iked heap overflow CVE-2026-19313, iked stack overflow CVE-2026-19318 and iked type confusion CVE-2026-19315 (unauthenticated remote code execution via crafted traffic); epm stack overflow CVE-2026-13086 in the deprecated Mobile Security feature; and Dimension CVE-2026-78174, session-ID and CSRF token exposure that can let a low-privileged administrator take over a super-admin session. SecurityWeek (Ionut Arghire, 1 September) matches those five at CVSS 9.3. Patch to Fireware OS 2026.2.2, 12.12.2 or 12.5.20 and Dimension 2.3.1. WatchGuard also shipped additional high- and medium-severity fixes in the same wave (iked denial-of-service and Dimension SQL injection, CSRF, SSRF and related issues among them); this card does not list every CVE. The vendor is not aware of exploitation of these defects.

Product
WatchGuard Fireware OS (iked / epm) and WatchGuard Dimension
Versions
Fireware OS before 2026.2.2 / 12.12.2 / 12.5.20; Dimension before 2.3.1
CVSS
(CVSS 4.0, WatchGuard CNA; five criticals)
Exploited in Australia?
unknown
Patch to
Fireware OS 2026.2.2 / 12.12.2 / 12.5.20; Dimension 2.3.1

Primary: WatchGuard PSIRT advisories (27 Aug 2026) · Vendor: WatchGuard PSIRT · CVE: CVE-2026-19313, CVE-2026-19318, CVE-2026-19315, CVE-2026-13086, CVE-2026-78174 · SecurityWeek (1 Sep 2026)

vulnerabilities network