An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with an AES-GCM cipher suite.
This vulnerability affects Firebox systems configured with a branch office VPN with IKEv2 to a dynamic peer or a mobile VPN with IKEv2
WatchGuard is not aware of any exploitation of this vulnerability in the wild.
Fireware OS 2026.3.2, Fireware OS 2026.2.3, Fireware OS 12.12.3, Fireware OS 12.5.21