All CVEs
Vulnerability intelligence

CVE-2026-13368

CWE-416

WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server.

CVSS Score
9.2
Critical
EPSS — Exploit Probability
1.0%
Riskier than 60% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered Jul 3, 2026 · latest Jul 3, 2026

Coverage timeline