{"id":"CVE-2026-18145","title":"A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending…","summary":"A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending…","severity":"high","cvss":8.6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-121"],"vendor":"WatchGuard","product":"Fireware OS","affected":["fireware_os >= 2026.3 < 2026.3.2","fireware_os >= 2025.0 < 2026.2.3","fireware_os >= 12.0 < 12.12.3","fireware_os >= 12.0 < 12.5.21"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T00:16:36.003","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-18145","references":[{"url":"https://psirt.watchguard.com/CVE-2026-18145","label":"5d1c2695-1a31-4499-88ae-e847036fd7e3"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-09-29T23:52:50.548Z","slug":"CVE-2026-18145","body":"## Overview\n\nA stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending a specially crafted management request.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":47.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}