CVE-2026-13368

Summary

WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server.

Affected Software

VendorProductVersion RangeStatus
WatchGuardFireware OS2025.1 < 2026.2.1affected
WatchGuardFireware OS12.0 < 12.12.1unaffected
WatchGuardFireware OS11.10.2 <= 11.12.4+541730unaffected
WatchGuardFireware OS12.0 < 12.5.19affected

Weaknesses

  • CWE-416: CWE-416

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References