CVE-2026-13368
WatchGuard Firebox Race Condition and Use-After-Free in Mobile VPN with IKEv2 LDAP Authentication
CVSS Score
0.0
EPSS Score
0.8%
EPSS Percentile
53th
WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server.
| CWE | CWE-416 |
| Vendor | watchguard |
| Product | fireware os |
| Published | Jul 2, 2026 |
| Last Updated | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for watchguard fireware os
Be the first to know when new unknown vulnerabilities affecting watchguard fireware os are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
WatchGuard / Fireware OS
2025.1 < 2026.2.1
WatchGuard / Fireware OS
12.0 < 12.5.19
References
Credits
Cody Sixteen