CVE-2026-86133

An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message, resulting in a denial of service.

  • Published Sep 30, 2026
  • CVSS 8.2 high
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-86133 at the National Vulnerability Database