Description
An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message, resulting in a denial of service.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Fireware OS 2026.3.2, Fireware OS 2026.2.3, Fireware OS 12.12.3, Fireware OS 12.5.21
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://psirt.watchguard.com/CVE-2026-86133 |
|
History
Tue, 29 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message, resulting in a denial of service. | |
| Title | Fireware OS Pre-Authentication Integer Underflow in iked Allows Remote Denial of Service | |
| First Time appeared |
Watchguard
Watchguard fireware Os |
|
| Weaknesses | CWE-1284 CWE-191 |
|
| CPEs | cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Watchguard
Watchguard fireware Os |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: WatchGuard
Published:
Updated: 2026-09-29T23:05:47.652Z
Reserved: 2026-09-05T03:00:39.457Z
Link: CVE-2026-86133
No data.
Status : Received
Published: 2026-09-30T00:16:37.087
Modified: 2026-09-30T00:16:37.087
Link: CVE-2026-86133
No data.
OpenCVE Enrichment
No data.