logo

Threat Actors Exploit Zero-Day in WatchGuard Firebox Devices

ID: a53c534a-9dc4-5b06-9438-7de0d1b71804

STIX ID: report--a53c534a-9dc4-5b06-9438-7de0d1b71804

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2025-12-22

Date Updated: 2026-04-21

Author: Rob Wright

...
...

WatchGuard disclosed a critical zero-day (CVE-2025-14733) in Fireware OS affecting Firebox appliances that allows remote code execution via an out-of-bounds write in the IKED process; the vendor reports active exploitation, published an advisory with IoCs and mitigations, and urged immediate patching. CISA added the flaw to its KEV catalog, WatchGuard released a patch on 18 December, and Shadowserver scans found roughly 125,000 potentially vulnerable Firebox IPs worldwide, indicating broad exposure of edge devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.