CVE-2026-13368Patch(watchguard / firebox_cloud)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch watchguard firebox_cloud systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firebox_cloud
  • firebox_m270
  • firebox_m290
  • firebox_m295

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 5 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 10 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 8 mentions (2026-07-03); latest day: 1
  • 12 total mentions across 5 days

Affected systems

Vendors
Products
firebox_cloudfirebox_m270firebox_m290firebox_m295firebox_m370firebox_m390firebox_m395firebox_m440firebox_m4600firebox_m470

2 versions affected across 39 products

Deep dive

Activity timeline12 mentions / 5d
02468Mentions · 2026-07-03: 8Mentions · 2026-07-04: 1Mentions · 2026-07-08: 1Mentions · 2026-07-15: 1Mentions · 2026-08-06: 1Patch / Workaround · 2026-07-03: 4Patch / Workaround · 2026-07-04: 1Patch / Workaround · 2026-07-08: 1Patch / Workaround · 2026-08-06: 1Technical Details · 2026-07-03: 7Technical Details · 2026-07-04: 1Technical Details · 2026-07-08: 1Technical Details · 2026-08-06: 107-0307-0407-0807-1508-06
Signal classification3 categories
Patch
758.3%
Disclosure
325.0%
General
216.7%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-07-038
Disclosure3General1Patch4
2026-07-041
Patch1
2026-07-081
Patch1
2026-07-151
General1
2026-08-061
Patch1
Full discourse12 posts
  • Daily CyberSecurity@the_yellow_fall
    Patch

    WatchGuard Firebox vulnerabilities include a critical unauthenticated RCE (CVE-2026-13368, CVSS 9.2) plus six more Fireware OS flaws. Patch now. #WatchGuard #Firebox #CVE202613368 #FirewareOS #CyberSecurity http://securityonline.info/watchguard-firebox-vulnerabilities/

    Post summary

    The tweet announces critical WatchGuard Firebox vulnerabilities, specifies RCE and CVSS details, and calls for immediate patching.

    04071736
    12.9K followersView on X
  • connect24h@connect24h
    Patch

    あぁ、WatchGuardお前もか。WatchGuard FireboxのVPN RCEは、境界機器を置いている組織の初動案件です。CVE-2026-13368、CVSS 9.2。Mobile User VPN with IKEv2で外部LDAP認証を使う構成は、認証前にiked権限でcode executionされる可能性があります。 対象はFireware OS 11.0-11.12.4_Update1、12.0-12.12、12.5-12.5.18、2025.1-2026.2。修正版は2026.2.1/12.12.1、T15/T35の12.5.xは未修正、11.xはEOL。見るべきは、IKEv2 LDAP設定の有無、外部公開、ikedのcrash/restart、VPN認証失敗の急増。VPN機器は「落ちたら困る」ではなく「抜かれたら全社が困る」資産として扱ってほしい。 #セキュリティ

    Post summary

    The post warns of a severe RCE in WatchGuard Firebox VPN (CVE‑2026‑13368) with detailed exploit context and provides patch identifiers, urging updates.

    10020477
    6.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-13368 WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthe… https://www.cve.org/CVERecord?id=CVE-2026-13368

    Post summary

    The text announces CVE‑2026‑13368, a use‑after‑free race condition in WatchGuard Fireware OS affecting LDAP authentication for Mobile User VPN with IKEv2.

    01010793
    57.7K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical #vulnerability in #WatchGuard #Firebox. CVE-2026-13368 CVSS: 9.2. When a Mobile VPN with IKEv2 is configured to use an external LDAP authentication server, an attacker can remotely execute code #RCE! Read https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00023 and #Patch #Patch #Patch

    Post summary

    The tweet warns of a high‑severity RCE vulnerability (CVE‑2026‑13368) in WatchGuard Firebox Mobile VPN, cites CVSS 9.2, and directs readers to a vendor advisory that provides patch information.

    01000330
    7.2K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 『A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process』 CVE-2026-13368 WatchGuard Firebox Race Condition and Use-After-Free in Mobile VPN with IKEv2 LDAP Authentication https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00023

    Post summary

    WatchGuard has disclosed a race condition and use‑after‑free in Mobile VPN that allows remote unauthenticated attackers to execute arbitrary code in the iked process. No patches or exploits are referenced in the text.

    00010502
    6.9K followersView on X
  • Ing. Stgo. Diaz@Smarteck_cl
    Patch

    🔥 WatchGuard va por su tercer parche crítico en apenas 10 meses para el mismo componente IKEv2 de Firebox, algo que debería encender alarmas en cualquier equipo de seguridad. La falla CVE-2026-13368 tiene CVSS 9.2 y permite ejecución remota de código sin autenticación contra equipos Firebox expuestos a internet. Los dispositivos legacy que siguen sin actualizar son el punto más débil de cualquier perímetro con VPN IKEv2 activo. Quieres conocer más novedades tecnológicas? Sigue a @smarteck_cl y guarda, para tus futuras referencias. #WatchGuard #CVE #Ciberseguridad https://squirrelvpn.com/news/watchguard-critical-ikev2-patch-cve-2026-13368

    Post summary

    The post announces WatchGuard’s third critical patch for IKEv2 (CVE‑2026‑13368), highlighting a CVSS 9.2 remote code execution flaw, but provides no proof‑of‑concept or exploitation details.

    0000059
    1.9K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos WatchGuard ❗ CVE-2026-13368 ❗ CVE-2026-13084 ❗ CVE-2026-13050 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-watchguard-5/ https://t.co/18T6zx1S9J

    Post summary

    The tweet lists three WatchGuard CVEs and links to a source for additional information, but it lacks any technical details, PoC, or patch guidance.

    00000194
    6.7K followersView on X
  • Israel@f1tym1
    Patch

    WatchGuard patched a critical RCE vulnerability (CVE-2026-13368) in Firebox appliances, leaving legacy T15/T35 models vulnerable without a patch https://ift.tt/EhoOAqR

    Post summary

    WatchGuard released a patch for CVE-2026-13368, a critical RCE in Firebox appliances, but legacy T15/T35 models remain vulnerable if not updated.

    0000056
    1.0K followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-13368 (CVSS 9.2) impacts WatchGuard Fireware OS LDAP auth in Mobile User VPN with IKEv2. Affected organizations should assess exposure and apply updates. https://nvd.nist.gov/vuln/deta… via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/oS8MdM9LrM

    Post summary

    The tweet highlights the high‑severity CVE-2026‑13368 affecting WatchGuard Fireware OS LDAP authentication and urges organizations to assess exposure and deploy available updates.

    0000069
    92 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨CRITICAL - WatchGuard Fireware OS Use-After-Free in LDAP Authentication (CVE-2026-13368) WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this to execute arbitrary code in the context of the iked process on Fireboxes configured to use an external LDAP authentication server. 👉Affected: Fireware OS 11.0 – 11.12.4_Update1, 12.0 – 12.12, and 2025.1 – 2026.2 Action: Update to the latest patched version of Fireware OS as soon as possible.

    Post summary

    The tweet alerts users to a critical use‑after‑free vulnerability in WatchGuard Fireware OS that permits remote unauthenticated code execution, and urges immediate patching.

    00000132
    236 followersView on X
  • VulDB 🛡@vuldb
    General

    A severe vulnerability was disclosed for WatchGuard Fireware OS (CVE-2026-13368) https://vuldb.com/vuln/376018

    Post summary

    A severe vulnerability (CVE-2026-13368) was announced for WatchGuard Fireware OS, with a link to a vulnerability report but no further technical or exploit details.

    00000123
    2.3K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-13368 WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthe… https://www.cve.org/CVERecord?id=CVE-2026-13368 ----- Traducción: CVE-2026-13368 Wat… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑13368, describing a race condition that causes a use‑after‑free during LDAP authentication for WatchGuard Fireware OS’s Mobile User VPN with IKEv2, but provides no PoC, exploit, or mitigation details.

    0000063
    91 followersView on X
CPE platform detail41 entries

41 of 41 entries

PartVendorProductVersionTarget SWTarget HW
Appwatchguardfirebox_cloud---
HWwatchguardfirebox_m270---
HWwatchguardfirebox_m290---
HWwatchguardfirebox_m295---
HWwatchguardfirebox_m370---
HWwatchguardfirebox_m390---
HWwatchguardfirebox_m395---
HWwatchguardfirebox_m440---
HWwatchguardfirebox_m4600---
HWwatchguardfirebox_m470---
HWwatchguardfirebox_m4800---
HWwatchguardfirebox_m495---
HWwatchguardfirebox_m5600---
HWwatchguardfirebox_m570---
HWwatchguardfirebox_m5800---
HWwatchguardfirebox_m590---
HWwatchguardfirebox_m595---
HWwatchguardfirebox_m670---
HWwatchguardfirebox_m690---
HWwatchguardfirebox_m695---
HWwatchguardfirebox_nv5---
HWwatchguardfirebox_t115-w---
HWwatchguardfirebox_t125---
HWwatchguardfirebox_t125-w---
HWwatchguardfirebox_t145---
HWwatchguardfirebox_t145-w---
HWwatchguardfirebox_t15---
HWwatchguardfirebox_t185---
HWwatchguardfirebox_t20---
HWwatchguardfirebox_t25---
HWwatchguardfirebox_t35---
HWwatchguardfirebox_t40---
HWwatchguardfirebox_t45---
HWwatchguardfirebox_t55---
HWwatchguardfirebox_t70---
HWwatchguardfirebox_t80---
HWwatchguardfirebox_t85---
HWwatchguardfireboxv---
OSwatchguardfireware---
OSwatchguardfireware11.12.4--
OSwatchguardfireware11.12.4--

Explore more