CVE-2026-18145: fallo de gravedad alta en WatchGuard Fireware OS
Fireware OS Stack-based Buffer Overflow in spamd Allows Remote Code Execution
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.6epss 0.3%
probabilidad de explotación
0.3%top 74% de las CVE
explotación observada
noninguna fuente lo reporta
A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending a specially crafted management request.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
WatchGuard · Fireware OSCVEs relacionadas — WatchGuard Fireware OS
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-9242CRITICALWatchGuard Firebox iked Out of Bounds Write VulnerabilityEPSS 91.3%KEVCVE-2025-14733CRITICALWatchGuard Firebox iked Out of Bounds Write VulnerabilityEPSS 26.5%KEVCVE-2022-31749MEDIUMAuthenticated arbitrary file read/write in WatchGuard Fireware OSEPSS 1.3%CVE-2026-3987HIGHWatchGuard Firebox Arbitrary File Write vis Path Traversal in Fireware Web UIEPSS 1.1%CVE-2024-5974HIGHFirebox Authenticated Buffer Overflow VulnerabilityEPSS 1.1%CVE-2026-13368CRITICALWatchGuard Firebox Race Condition and Use-After-Free in Mobile VPN with IKEv2 LDAP AuthenticationEPSS 0.9%
Referencias
https://psirt.watchguard.com/CVE-2026-18145