CVE-2026-18145

Fireware OS Stack-based Buffer Overflow in spamd Allows Remote Code Execution

High 8.6 CVSS v4.0 › Published 2026-09-29Updated 2026-09-29

Summary #

A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending a specially crafted management request.

Product status #

ProductAffectedNot affected
Fireware OS
Default >= 2026.3, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3
T15/T35 >= 12.0, < 12.5.21>= 12.5.21

Weakness Type and Impact #

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Fireware OS 2026.3.2, Fireware OS 2026.2.3, Fireware OS 12.12.3, Fireware OS 12.5.21

References #

    Credits #

    • Nicholas Zubrisky (@NZubrisky) of TrendAI Researchfinder