High severity8.1NVD Advisory· Published Jul 3, 2026· Updated Aug 28, 2026
CVE-2026-13368
CVE-2026-13368
Description
WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*range: >=2025.1,<2026.2.1
- cpe:2.3:o:watchguard:fireware:11.12.4:-:*:*:*:*:*:*
- cpe:2.3:o:watchguard:fireware:11.12.4:u1:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
2- www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00023nvdVendor Advisory
- psirt.watchguard.com/CVE-2026-13368nvdBroken Link
News mentions
0No linked articles in our index yet.