CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

WatchGuard Fireware OS iked pre-auth use-after-free RCE (IKEv2/LDAP path, CVSS 9.2)

cve · CVE-2026-13368

Coverage
1
first 2026-07-03 → last 2026-07-03
Latest activity
2026-09-29
CVE-2026-13368, WatchGuard Firebox: pre-auth RCE in the IKEv2 VPN daemon (CVSS 9.2)
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, technology
Sources cited
2
2 hosts

Action items (3)

Do-now tasks recorded on the entries about CVE-2026-13368, newest first. Check the date before acting on an older one.

  • Patch internet-facing WatchGuard Fireboxes on Fireware 2025.1 to 2026.2 to 2026.2.1 now if Mobile VPN with IKEv2 uses an external LDAP authentication server.
    2026-07-03CVE-2026-13368
  • Upgrade T15/T35 Fireboxes on 12.x to 12.5.19 and EUCC builds to 12.11.9 where Mobile VPN with IKEv2 uses an external LDAP server.
    2026-07-03CVE-2026-13368
  • Hunt Firebox syslog/Traffic Monitor for unexplained iked crashes or restarts correlating with inbound UDP/500 and UDP/4500, and review the LDAP server's bind logs for malformed/high-frequency binds from the Firebox client identity.
    2026-07-03CVE-2026-13368

Defender insights

What each entry about CVE-2026-13368 tells a defender to do, newest first.

2026-07-03HIGHCVE-2026-13368, WatchGuard Firebox: pre-auth RCE in the IKEv2 VPN daemon (CVSS 9.2)

Story timeline

  1. 2026-07-03CVE-2026-13368, WatchGuard Fireware OS: pre-auth use-after-free RCE in the iked IKEv2/LDAP path (CVSS 9.2)
    trending-vulnerabilitiesCVE-2026-13368, WatchGuard Firebox: pre-auth RCE in the IKEv2 VPN daemon (CVSS 9.2)
ATT&CK techniques (2 across 2 tactics)

2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExternal Remote Services · Exploit Public-Facing Application
  • PersistenceExternal Remote Services

Initial Access TA0001

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-07-03/cve-2026-13368-watchguard-fireware-iked-pre-auth-rce · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-03/cve-2026-13368-watchguard-fireware-iked-pre-auth-rce · ATT&CK page ↗

Persistence TA0003

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-07-03/cve-2026-13368-watchguard-fireware-iked-pre-auth-rce · ATT&CK page ↗

Entries about WatchGuard Fireware OS iked pre-auth use-after-free RCE (IKEv2/LDAP path, CVSS 9.2) (1)

2026-07-03 · view entry permalink →

HIGHCVE-2026-13368updatedNATOA2

CVE-2026-13368, WatchGuard Fireware OS: pre-auth use-after-free RCE in the iked IKEv2/LDAP path (CVSS 9.2)

WatchGuard disclosed CVE-2026-13368 (CVSS 4.0 base 9.2, CWE-416 use-after-free), one of ten Fireware OS advisories published in the same cycle (WGSA-2026-00014 through -00023) (WatchGuard PSIRT, 2026-07-02). The flaw is a race condition producing a use-after-free in iked, the IKEv2 key-exchange daemon, reachable during LDAP authentication for Mobile VPN with IKEv2; a remote unauthenticated attacker who wins the race can execute code in the iked process context. The prerequisite (Mobile VPN with IKEv2 pointed at an external LDAP authentication server) is a common enterprise remote-access setup, and the CVSS 4.0 vector (AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H) reflects the probabilistic race rather than a deterministic single-shot primitive. At publication the advisory listed Fireware OS 11.0 through 2026.2 as affected, gave fixed builds 2026.2.1 and 12.12.1, marked the 12.5.x branch (T15/T35 models) "Unresolved" and gave 11.x End-of-Life status with no fix and no workaround. The current affected range and fixes are in the update below. BSI CERT-Bund relayed the full ten-advisory batch as WID-SEC-2026-2193, rating it "hoch" (BSI CERT-Bund, 2026-07-03). No public PoC or in-the-wild exploitation was reported at publication. Mapped to T1190 Exploit Public-Facing Application for initial access and T1133 External Remote Services for the exposed IKEv2/Mobile-VPN surface.

A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server.

WatchGuard PSIRT (WGSA-2026-00023)
Updaterun 2026-09-29T2134Z-auditsummarycvessourcesactionstechniquesclassificationbody

The branch this entry recorded as unresolved now has a fix. WatchGuard's advisory lists T15/T35 appliances on Fireware OS 12.5.x as affected below 12.5.19 and fixed from 12.5.19, and EUCC builds as fixed from 12.11.9, alongside the 2026.2.1 fix that shipped at disclosure (WatchGuard PSIRT, CVE-2026-13368). The revised advisory also narrows the affected range. On the standard platform it now lists only 2025.1 to below 2026.2.1 as affected, and it lists the 12.x line below 12.12.1 and 11.10.2 to 11.12.4 as not affected, where the advisory at publication gave every build from 11.0 through 2026.2. T15/T35 owners who fell back to disabling LDAP-backed Mobile VPN with IKEv2 can now upgrade instead. WatchGuard still states it is not aware of any exploitation in the wild. The advisory itself has moved to psirt.watchguard.com, where the per-CVE page carries the text quoted above.

vulnerability03 Jul 18:25Zmulti-sourceOpen finding →

explore in graph

Where this entity is cited

  • Vulns1

Source distribution

  • psirt.watchguard.com1 (50%)
  • wid.cert-bund.de1 (50%)