Three of WatchGuard's 27 new flaws can be exploited without logging in

WatchGuards eget varsel om å oppdatere Firebox
Image: WatchGuard. Source: WatchGuard (opens in a new tab)

WatchGuard disclosed 27 vulnerabilities in Fireware OS and Dimension. Five of them are rated critical under CVSS 4.0. Three of the Fireware OS flaws, CVE-2026-19313, CVE-2026-19315 and CVE-2026-19318, could allow code execution without authentication if an attacker sends specially crafted traffic to the IKE daemon. CVE-2026-13086 could allow code execution as root for an attacker who is already network-adjacent, through the deprecated Mobile Security service.

The fifth critical flaw sits in Dimension. CVE-2026-78174 could let an administrator with few privileges extract a Super Administrator session token from the diagnostic logs and take over the account. WatchGuard says it has seen no indication that the Fireware flaws have been exploited. Fireware OS should be updated to 2026.2.2, 12.12.2 or 12.5.20 depending on the branch the appliance sits on, and Dimension to 2.3.1.

What this means for you if you have a Firebox at the edge

A firewall is the one system that has to be reachable for everything else to be protected. IKE listens because the VPN has to work, so a flaw in that particular service lands on the organisations that did what they were supposed to do. Our assessment is that this update should not wait for the ordinary maintenance window. The vendor seeing no exploitation says something about today and nothing about next week.

The Dimension flaw deserves a thought of its own. A session token that ends up in a diagnostic log is a reminder that logs hold secrets, and that access to them belongs under the same discipline as access to the system they describe. If you have given several colleagues read access to the operations logs because it was practical, that is the decision this advisory puts to the test.

Berigo recommends

  • Update Fireware OS to 2026.2.2, 12.12.2 or 12.5.20, according to the branch the appliance sits on.
  • Update Dimension to 2.3.1, and review who holds administrator access there.
  • Turn off Mobile Security if the service is still in use anywhere on the network.
  • Restrict who can reach the management interface, and never expose it to the internet.
  • Replace the Super Administrator sessions once the update is in place.

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch