logo

CISA warns of WatchGuard firewall flaw exploited in attacks

ID: 78fc5beb-a6a0-5a52-99ff-dc28e31b4373

STIX ID: report--78fc5beb-a6a0-5a52-99ff-dc28e31b4373

Feed Name: Bleeping Computer

Threat Score
82/100

Date Published: 2025-11-13

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

CISA has warned that a critical, actively exploited out-of-bounds write vulnerability (CVE-2025-9242) in WatchGuard Firebox firewalls running Fireware OS 11.x–2025.1 can enable remote code execution; the flaw was added to CISA's KEV list and federal agencies are required to patch by December 3. WatchGuard released patches in September, but large numbers of vulnerable appliances remain exposed (Shadowserver ~54,000), and exploitation is ongoing—organizations are advised to apply vendor mitigations or discontinue use if unavailable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.