WatchGuard has released patches for over two dozen vulnerabilities, including five critical-severity flaws leading to remote code execution (RCE) and account takeover.

Three of the critical bugs impact the iked process of Fireware OS, the core Internet Key Exchange (IKE) daemon that handles cryptographic key establishment and manages IPsec VPN negotiations over the IKEv1 and IKEv2 protocols.

Exploitable without authentication, the three security defects are a heap buffer overflow (CVE-2026-19313), a stack-based buffer overflow (CVE-2026-19318), and a type confusion (CVE-2026-19315).

Attackers could send specially crafted network traffic to trigger each of these vulnerabilities and achieve RCE, WatchGuard says.

WatchGuard also patched a critical stack-based buffer overflow bug (CVE-2026-13086) in the Endpoint Protection Manager (epm) service that is used by the deprecated Mobile Security feature in Fireware OS, which could lead to RCE.