WATCHGUARD has issued patches for more than 25 vulnerabilities, including five critical ones that could lead to remote code execution (RCE) and account takeover. Key vulnerabilities include heap and stack buffer overflows in the IKE daemon of Fireware OS, which are exploitable without authentication. The company has also patched additional vulnerabilities in the Endpoint Protection Manager and WatchGuard Dimension. All critical vulnerabilities have a CVSS score of 9.3.
Updates are available in Fireware OS versions 2026.2.2, 12.12.2, and 12.5.20, and Dimension version 2.3.1. WatchGuard is not aware of any real-world exploitation of these vulnerabilities.