CVE-2026-18145

A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending a specially crafted management request.

  • Published Sep 30, 2026
  • CVSS 8.6 high
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-18145 at the National Vulnerability Database