2026-07-03HIGHCVE-2026-13368, WatchGuard Firebox: pre-auth RCE in the IKEv2 VPN daemon (CVSS 9.2)
WatchGuard Fireware OS iked pre-auth use-after-free RCE (IKEv2/LDAP path, CVSS 9.2)
cve · CVE-2026-13368
Coverage
1
first 2026-07-03 → last 2026-07-03
Latest activity
2026-09-29
CVE-2026-13368, WatchGuard Firebox: pre-auth RCE in the IKEv2 VPN daemon (CVSS 9.2)
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, technology
Sources cited
2
2 hosts
Action items (3)
Do-now tasks recorded on the entries about CVE-2026-13368, newest first. Check the date before acting on an older one.
- Patch internet-facing WatchGuard Fireboxes on Fireware 2025.1 to 2026.2 to 2026.2.1 now if Mobile VPN with IKEv2 uses an external LDAP authentication server.2026-07-03CVE-2026-13368
- Upgrade T15/T35 Fireboxes on 12.x to 12.5.19 and EUCC builds to 12.11.9 where Mobile VPN with IKEv2 uses an external LDAP server.2026-07-03CVE-2026-13368
- Hunt Firebox syslog/Traffic Monitor for unexplained iked crashes or restarts correlating with inbound UDP/500 and UDP/4500, and review the LDAP server's bind logs for malformed/high-frequency binds from the Firebox client identity.2026-07-03CVE-2026-13368
Defender insights
What each entry about CVE-2026-13368 tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExternal Remote Services · Exploit Public-Facing Application
- PersistenceExternal Remote Services
Initial Access TA0001
T1133External Remote Services×1
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Evidence: 2026-07-03/cve-2026-13368-watchguard-fireware-iked-pre-auth-rce · ATT&CK page ↗
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-03/cve-2026-13368-watchguard-fireware-iked-pre-auth-rce · ATT&CK page ↗
Persistence TA0003
T1133External Remote Services×1
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Evidence: 2026-07-03/cve-2026-13368-watchguard-fireware-iked-pre-auth-rce · ATT&CK page ↗
Entries about WatchGuard Fireware OS iked pre-auth use-after-free RCE (IKEv2/LDAP path, CVSS 9.2) (1)
Where this entity is cited
Source distribution
- psirt.watchguard.com1 (50%)
- wid.cert-bund.de1 (50%)