CVE-2026-13368, WatchGuard Fireware OS: pre-auth use-after-free RCE in the iked IKEv2/LDAP path (CVSS 9.2)
CVE-2026-13368, WatchGuard Firebox: pre-auth RCE in the IKEv2 VPN daemon (CVSS 9.2)
Defender actions
- Patch internet-facing WatchGuard Fireboxes on Fireware 2025.1 to 2026.2 to 2026.2.1 now if Mobile VPN with IKEv2 uses an external LDAP authentication server.
- Upgrade T15/T35 Fireboxes on 12.x to 12.5.19 and EUCC builds to 12.11.9 where Mobile VPN with IKEv2 uses an external LDAP server.
- Hunt Firebox syslog/Traffic Monitor for unexplained iked crashes or restarts correlating with inbound UDP/500 and UDP/4500, and review the LDAP server's bind logs for malformed/high-frequency binds from the Firebox client identity.
Analysis
WatchGuard disclosed CVE-2026-13368 (CVSS 4.0 base 9.2, CWE-416 use-after-free), one of ten Fireware OS advisories published in the same cycle (WGSA-2026-00014 through -00023) (WatchGuard PSIRT, 2026-07-02). The flaw is a race condition producing a use-after-free in iked, the IKEv2 key-exchange daemon, reachable during LDAP authentication for Mobile VPN with IKEv2; a remote unauthenticated attacker who wins the race can execute code in the iked process context. The prerequisite (Mobile VPN with IKEv2 pointed at an external LDAP authentication server) is a common enterprise remote-access setup, and the CVSS 4.0 vector (AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H) reflects the probabilistic race rather than a deterministic single-shot primitive. At publication the advisory listed Fireware OS 11.0 through 2026.2 as affected, gave fixed builds 2026.2.1 and 12.12.1, marked the 12.5.x branch (T15/T35 models) "Unresolved" and gave 11.x End-of-Life status with no fix and no workaround. The current affected range and fixes are in the update below. BSI CERT-Bund relayed the full ten-advisory batch as WID-SEC-2026-2193, rating it "hoch" (BSI CERT-Bund, 2026-07-03). No public PoC or in-the-wild exploitation was reported at publication. Mapped to T1190 Exploit Public-Facing Application for initial access and T1133 External Remote Services for the exposed IKEv2/Mobile-VPN surface.
Cited evidence
A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server.
Updates1
The branch this entry recorded as unresolved now has a fix. WatchGuard's advisory lists T15/T35 appliances on Fireware OS 12.5.x as affected below 12.5.19 and fixed from 12.5.19, and EUCC builds as fixed from 12.11.9, alongside the 2026.2.1 fix that shipped at disclosure (WatchGuard PSIRT, CVE-2026-13368). The revised advisory also narrows the affected range. On the standard platform it now lists only 2025.1 to below 2026.2.1 as affected, and it lists the 12.x line below 12.12.1 and 11.10.2 to 11.12.4 as not affected, where the advisory at publication gave every build from 11.0 through 2026.2. T15/T35 owners who fell back to disabling LDAP-backed Mobile VPN with IKEv2 can now upgrade instead. WatchGuard still states it is not aware of any exploitation in the wild. The advisory itself has moved to psirt.watchguard.com, where the per-CVE page carries the text quoted above.
Sources2
Revision history
- Published 2026-07-03T1809Z-intel
- Update 2026-09-29T2134Z-audit
WatchGuard revised its advisory and moved it to psirt.watchguard.com. T15/T35 appliances are now fixed in 12.5.19 and EUCC builds in 12.11.9, the two branches unresolved at publication. The affected range is also narrower: on the standard platform only 2025.1 to below 2026.2.1 is listed as affected, with the 12.x line and 11.10.2 to 11.12.4 listed as not affected. The summary, the CVE record and the actions follow the current advisory. WatchGuard still reports no exploitation in the wild. The entry also gains the ATT&CK mapping its analysis already described and an Admiralty rating of A2.
Changed: summary cves sources actions techniques classification body
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.