ctipilot.ch

WatchGuard Fireware OS iked pre-auth use-after-free RCE (IKEv2/LDAP path, CVSS 9.2)

cve · CVE-2026-13368

Coverage timeline
1
first 2026-07-03 → last 2026-07-03
Peak priority
high
1 high
Sources cited
2
2 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
2
pinned v19.1 · see below

ATT&CK techniques

2 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-07-03/cve-2026-13368-watchguard-fireware-iked-pre-auth-rce · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-03/cve-2026-13368-watchguard-fireware-iked-pre-auth-rce · ATT&CK page ↗

Persistence TA0003

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-07-03/cve-2026-13368-watchguard-fireware-iked-pre-auth-rce · ATT&CK page ↗

Story timeline

  1. 2026-07-03CVE-2026-13368 — WatchGuard Fireware OS: pre-auth use-after-free RCE in the iked IKEv2/LDAP path (CVSS 9.2)
    trending-vulnerabilitiesCVE-2026-13368 — WatchGuard Firebox: pre-auth RCE in the IKEv2 VPN daemon (CVSS 9.2)

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • watchguard.com1 (50%)
  • wid.cert-bund.de1 (50%)

explore in graph

Entries about WatchGuard Fireware OS iked pre-auth use-after-free RCE (IKEv2/LDAP path, CVSS 9.2) (1)

2026-07-03 · view entry permalink →

CVE-2026-13368 — WatchGuard Fireware OS: pre-auth use-after-free RCE in the iked IKEv2/LDAP path (CVSS 9.2)

WatchGuard disclosed CVE-2026-13368 (CVSS 4.0 base 9.2, CWE-416 use-after-free), one of ten Fireware OS advisories published in the same cycle (WGSA-2026-00014 through -00023) (WatchGuard PSIRT, 2026-07-02). The flaw is a race condition producing a use-after-free in iked, the IKEv2 key-exchange daemon, reachable during LDAP authentication for Mobile VPN with IKEv2; a remote unauthenticated attacker who wins the race can execute code in the iked process context. The prerequisite — Mobile VPN with IKEv2 pointed at an external LDAP authentication server — is a common enterprise remote-access setup, and the CVSS 4.0 vector (AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H) reflects the probabilistic race rather than a deterministic single-shot primitive. Affected builds span Fireware OS 11.0 through 2026.2; WatchGuard lists fixed builds 2026.2.1 and 12.12.1, marks the 12.5.x branch (T15/T35 models) "Unresolved" at publication, and gives 11.x End-of-Life status with no fix and no workaround. BSI CERT-Bund relayed the full ten-advisory batch as WID-SEC-2026-2193, rating it "hoch" (BSI CERT-Bund, 2026-07-03). No public PoC or in-the-wild exploitation is reported as of this writing. Mapped to T1190 Exploit Public-Facing Application for initial access and T1133 External Remote Services for the exposed IKEv2/Mobile-VPN surface.

A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server.

WatchGuard PSIRT (WGSA-2026-00023)
vulnerability03 Jul 18:25Zmulti-sourceOpen finding ↗