
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-13383 is an Out-of-bounds Write vulnerability (CWE-787) in the WatchGuard Fireware OS ikestubd process that allows an authenticated privileged user to execute arbitrary code via specially crafted requests to the Management Web UI. It affects Fireware OS versions 12.1 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2. The vulnerability was published on July 3, 2026, and has a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 8.6 (High) (GitHub Advisory, WatchGuard Advisory).
The vulnerability is classified as CWE-787 (Out-of-bounds Write), occurring within the ikestubd process of WatchGuard Fireware OS — a daemon associated with IKE (Internet Key Exchange) stub functionality used in VPN operations. An attacker can trigger the out-of-bounds write by sending specially crafted HTTP requests to the Management Web UI, causing the process to write data beyond the bounds of an allocated buffer, which can be leveraged to achieve arbitrary code execution. Exploitation requires network access to the Management Web UI and authenticated privileged credentials, meaning the attack vector is network-based but the attack surface is limited to privileged administrative accounts (GitHub Advisory, WatchGuard Advisory).
Successful exploitation allows an authenticated privileged attacker to execute arbitrary code on the affected WatchGuard Fireware OS system, resulting in high impact to confidentiality, integrity, and availability of the vulnerable system. An attacker with existing administrative access could use code execution to pivot further within the network, exfiltrate sensitive VPN configuration data or credentials, modify firewall rules, or disrupt network security services. Because WatchGuard appliances function as network security gateways, compromise could expose the broader protected network to further attack (GitHub Advisory, WatchGuard Advisory).
As of the time of publication, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.43–0.55%, placing it around the 42nd percentile for exploitation probability within 30 days. The NVD SSVC assessment also indicates exploitation status as "none" and notes the vulnerability is not automatable, as it requires authenticated privileged access. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
ikestubd process via the Management Web UI, designed to trigger an out-of-bounds write condition in the process's buffer handling logic.ikestubd process writes data beyond the intended buffer boundary, potentially corrupting adjacent memory.ikestubd daemon in system logs.ikestubd process; unusual process activity on the Fireware appliance inconsistent with normal VPN or management operations.WatchGuard has released patched versions addressing this vulnerability: Fireware OS 12.12.1 (for the 12.x branch) and 2026.2.1 (for the 2025.x/2026.x branch); users should upgrade to these or later versions immediately (WatchGuard Advisory). As interim mitigations, administrators should restrict access to the Management Web UI to trusted IP addresses only, enforce strong multi-factor authentication for privileged accounts, and implement network segmentation to prevent unauthorized access to the management interface. Monitoring for anomalous authenticated requests to the Management Web UI is also recommended.
Coverage of CVE-2026-13383 has been limited to automated vulnerability tracking platforms and security news aggregators such as SecurityOnline.info and INCIBE-CERT, with no notable researcher commentary or significant social media discussion identified at this time (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."