WatchGuard patches critical Fireware OS and Dimension flaws

WatchGuard patched 26 vulnerabilities in Fireware OS and Dimension, including five critical flaws-three unauthenticated iked bugs that can allow remote code execution.
WatchGuard released patches for more than two dozen vulnerabilities affecting Fireware OS and its Dimension management platform in security advisories published by the company. Five of the fixes address critical defects that could lead to remote code execution or account takeover.
Three of the critical flaws target the iked daemon, the Internet Key Exchange (IKE) service that negotiates IPsec VPN connections. The defects are a heap buffer overflow (CVE-2026-19313), a type confusion (CVE-2026-19315) and a stack-based buffer overflow (CVE-2026-19318). Each can be triggered by specially crafted network traffic and are exploitable without authentication, creating the potential for an attacker on the network to execute code on the appliance.
WatchGuard also patched a stack-based buffer overflow in the Endpoint Protection Manager (epm) service tied to the deprecated Mobile Security feature in Fireware OS (CVE-2026-13086). That bug could enable remote code execution. In Dimension, the company fixed CVE-2026-78174, which could allow a low-privileged administrator to extract a super administrator’s session ID and CSRF tokens and take over that account. All five critical issues have a CVSS score of 9.3.
The fixes appear in Fireware OS releases 2026.2.2, 12.12.2 and 12.5.20, and in Dimension version 2.3.1. The updates also resolve seven high-severity Fireware OS vulnerabilities, six of which affect iked and can cause denial-of-service, and five high-severity Dimension flaws that could lead to arbitrary command execution, tampering with the global administrator passphrase, or DoS. WatchGuard issued patches for 11 medium-severity issues as well, covering one more iked bug and ten in Dimension.
WatchGuard’s advisory states it is not aware of any of the patched vulnerabilities being exploited in the wild. The company directed customers to its security advisories for technical details and mitigation guidance. Customers running affected Firebox appliances and Dimension instances were urged to apply the updates. Administrators still using the deprecated Mobile Security component were advised to both patch the software and review their deployments for legacy services.








