---
schema: 1
kind: vulnerability
title: "CVE-2026-13368 — WatchGuard Fireware OS: pre-auth use-after-free RCE in the iked IKEv2/LDAP path (CVSS 9.2)"
headline: "CVE-2026-13368 — WatchGuard Firebox: pre-auth RCE in the IKEv2 VPN daemon (CVSS 9.2)"
summary: "WatchGuard patched a critical (CVSS 9.2) pre-authentication use-after-free in the iked IKEv2 daemon of Fireware OS (CVE-2026-13368) that a remote attacker can exploit for code execution on Fireboxes running Mobile VPN with IKEv2 backed by an external LDAP server. Any org exposing a Firebox VPN gateway with that configuration should patch now: WatchGuard's current advisory lists Fireware 2025.1 to 2026.2 as affected on the standard platform (fixed in 2026.2.1), T15/T35 appliances from 12.0 below 12.5.19 (fixed in 12.5.19) and EUCC builds below 12.11.9 (fixed in 12.11.9). No public PoC or in-the-wild exploitation is reported so far, but this is the exact edge-appliance RCE class that becomes a fast-follow mass-exploitation target."
discovered_at: "2026-07-03T18:25:00Z"
updated_at: "2026-09-29T23:34:31Z"
event_date: 2026-07-02
run_id: 2026-07-03T1809Z-intel
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - pre-auth
  - patch-available
regions:
  - global
sectors:
  - public-sector
  - technology
entities: []
techniques: [T1190, T1133]
cves:
  - id: CVE-2026-13368
    cvss: "9.2"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
    affected: "Per the current advisory: standard platform 2025.1 to below 2026.2.1; T15/T35 12.0 to below 12.5.19; EUCC 12.0 to below 12.11.9 (the advisory at publication listed 11.0 through 2026.2)"
    fixed: "2026.2.1 (standard platform); 12.5.19 (T15/T35); 12.11.9 (EUCC)"
sources:
  - url: "https://psirt.watchguard.com/CVE-2026-13368"
    publisher: WatchGuard PSIRT (WGSA-2026-00023)
    role: primary
  - url: "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2193"
    publisher: BSI CERT-Bund WID-SEC-2026-2193
    role: corroborating
closed_sources: []
evidence:
  - quote: "A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server."
    publisher: WatchGuard PSIRT (WGSA-2026-00023)
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "**Patch internet-facing WatchGuard Fireboxes on Fireware 2025.1 to 2026.2 to 2026.2.1 now** if Mobile VPN with IKEv2 uses an external LDAP authentication server."
  - "Upgrade T15/T35 Fireboxes on 12.x to 12.5.19 and EUCC builds to 12.11.9 where Mobile VPN with IKEv2 uses an external LDAP server."
  - "Hunt Firebox syslog/Traffic Monitor for unexplained iked crashes or restarts correlating with inbound UDP/500 and UDP/4500, and review the LDAP server's bind logs for malformed/high-frequency binds from the Firebox client identity."
migrated_from: null
updates:
  - at: "2026-09-29T23:34:31Z"
    run_id: 2026-09-29T2134Z-audit
    type: update
    summary: >
      WatchGuard revised its advisory and moved it to psirt.watchguard.com. T15/T35 appliances are now
      fixed in 12.5.19 and EUCC builds in 12.11.9, the two branches unresolved at publication. The
      affected range is also narrower: on the standard platform only 2025.1 to below 2026.2.1 is
      listed as affected, with the 12.x line and 11.10.2 to 11.12.4 listed as not affected. The
      summary, the CVE record and the actions follow the current advisory. WatchGuard still reports no
      exploitation in the wild. The entry also gains the ATT&CK mapping its analysis already described
      and an Admiralty rating of A2.
    fields: [summary, cves, sources, actions, techniques, classification, body]
---

WatchGuard disclosed CVE-2026-13368 (CVSS 4.0 base 9.2, CWE-416 use-after-free), one of ten Fireware OS advisories published in the same cycle (WGSA-2026-00014 through -00023) ([WatchGuard PSIRT, 2026-07-02](https://psirt.watchguard.com/CVE-2026-13368)). The flaw is a race condition producing a use-after-free in `iked`, the IKEv2 key-exchange daemon, reachable during LDAP authentication for Mobile VPN with IKEv2; a remote unauthenticated attacker who wins the race can execute code in the `iked` process context. The prerequisite — Mobile VPN with IKEv2 pointed at an external LDAP authentication server — is a common enterprise remote-access setup, and the CVSS 4.0 vector (`AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H`) reflects the probabilistic race rather than a deterministic single-shot primitive. At publication the advisory listed Fireware OS 11.0 through 2026.2 as affected, gave fixed builds 2026.2.1 and 12.12.1, marked the 12.5.x branch (T15/T35 models) "Unresolved" and gave 11.x End-of-Life status with no fix and no workaround. The current affected range and fixes are in the update below. BSI CERT-Bund relayed the full ten-advisory batch as WID-SEC-2026-2193, rating it "hoch" ([BSI CERT-Bund, 2026-07-03](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2193)). No public PoC or in-the-wild exploitation was reported at publication. Mapped to `T1190 Exploit Public-Facing Application` for initial access and `T1133 External Remote Services` for the exposed IKEv2/Mobile-VPN surface. **Defender takeaway:** internet-exposed UTM/VPN gateways with pre-auth memory-corruption RCE (the Fortinet/Ivanti/Citrix pattern) reliably attract fast-follow exploitation once detail surfaces — treat this as patch-now for the affected configuration, and where an upgrade has to wait, remove the vulnerable auth path in the meantime. Detection realistically lives in appliance-side crash telemetry and the backing LDAP server's bind logs, since the exploit hits before any VPN session is established.

## Update — 2026-09-29T23:34:31Z

The branch this entry recorded as unresolved now has a fix. WatchGuard's advisory lists T15/T35 appliances on Fireware OS 12.5.x as affected below 12.5.19 and fixed from 12.5.19, and EUCC builds as fixed from 12.11.9, alongside the 2026.2.1 fix that shipped at disclosure ([WatchGuard PSIRT, CVE-2026-13368](https://psirt.watchguard.com/CVE-2026-13368)). The revised advisory also narrows the affected range. On the standard platform it now lists only 2025.1 to below 2026.2.1 as affected, and it lists the 12.x line below 12.12.1 and 11.10.2 to 11.12.4 as not affected, where the advisory at publication gave every build from 11.0 through 2026.2. T15/T35 owners who fell back to disabling LDAP-backed Mobile VPN with IKEv2 can now upgrade instead. WatchGuard still states it is not aware of any exploitation in the wild. The advisory itself has moved to psirt.watchguard.com, where the per-CVE page carries the text quoted above.
