Vulnerability intelligence
CVE-2026-13368
WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server.
CVSS Score
9.2
Critical
EPSS — Exploit Probability
1.0%
Riskier than 60% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Jul 3, 2026 · latest Jul 3, 2026
Coverage timeline
-
WatchGuard patches critical Firebox RCE flaw CVE-2026-13368securityonline.info · Jul 3, 2026