A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending a specially crafted management request.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Fireware OS 2026.3.2, Fireware OS 2026.2.3, Fireware OS 12.12.3, Fireware OS 12.5.21
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://psirt.watchguard.com/CVE-2026-18145 |
|
History
Tue, 29 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending a specially crafted management request. | |
| Title | Fireware OS Stack-based Buffer Overflow in spamd Allows Remote Code Execution | |
| First Time appeared |
Watchguard
Watchguard fireware Os |
|
| Weaknesses | CWE-121 | |
| CPEs | cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Watchguard
Watchguard fireware Os |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WatchGuard
Published:
Updated: 2026-09-29T23:05:47.947Z
Reserved: 2026-07-28T18:56:32.068Z
Link: CVE-2026-18145
No data.
Status : Received
Published: 2026-09-30T00:16:36.003
Modified: 2026-09-30T00:16:36.003
Link: CVE-2026-18145
No data.
OpenCVE Enrichment
No data.
Weaknesses