Buffer Overflow Vulnerability in WatchGuard Fireware OS
CVE-2026-18145

8.6HIGH

Key Information:

Vendor

Watchguard

Vendor
CVE Published:
29 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-18145?

A stack-based buffer overflow vulnerability exists in the spamBlocker service of WatchGuard Fireware OS. This flaw allows an authenticated user with administrator rights to disrupt the service by sending a specially crafted management request. If exploited, this vulnerability can lead to service crashes or, under specific conditions, enable an attacker to execute arbitrary code.

Affected Version(s)

Fireware OS Default 2026.3 < 2026.3.2

Fireware OS Default 2025.0 < 2026.2.3

Fireware OS Default 12.0 < 12.12.3

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nicholas Zubrisky (@NZubrisky) of TrendAI Research
.