WatchGuard has issued patches for more than twenty vulnerabilities, prioritizing five critical ones that can lead to remote code execution and account takeover. Three critical issues have been identified within the iked process of Fireware OS, which is responsible for cryptographic key establishment and IPsec VPN negotiations using the IKEv1 and IKEv2 protocols. These vulnerabilities, which include a heap buffer overflow, a stack-based buffer overflow, and a type confusion, can be exploited without authentication by sending specially crafted network traffic. In addition to these, a stack-based buffer overflow in the Endpoint Protection Manager service, associated with the deprecated Mobile Security feature in Fireware OS, has been addressed. This flaw could also result in remote code execution.

Another significant vulnerability, affecting WatchGuard Dimension, allows low-privileged administrators to extract a super admin's session ID and CSRF tokens, potentially leading to account takeover. This flaw, alongside the others, has been assigned a CVSS score of 9.3. The necessary fixes are included in Fireware OS versions 2026.2.2, 12.12.2, and 12.5.20, as well as Dimension version 2.3.1. These updates also resolve several high-severity vulnerabilities in Fireware OS and Dimension, which could result in denial-of-service attacks or arbitrary command execution.

In total, WatchGuard rolled out patches for eleven medium-severity vulnerabilities, covering issues in both Fireware OS and Dimension. The company has stated that there is no evidence of these vulnerabilities being exploited in the wild. Detailed information on the updates can be found on WatchGuard's security advisories page.