ZeroHour
Product

Fireware OS

2 mentions in 7 days · 3 in 30 days · 3 total · first seen · last

Timeline

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

CISA confirms ransomware gangs are exploiting critical unauthenticated RCE CVE-2025-14733 in WatchGuard Firebox firewalls, with roughly 9,000 devices still unpatched.

CVE-2025-14733 is an out-of-bounds write in WatchGuard Fireware OS allowing unauthenticated remote code execution, exploitable on firewalls configured for IKEv2 VPN and potentially even after the configuration was deleted if a static branch-office VPN peer remains. WatchGuard released patches in December and confirmed in-the-wild exploitation; Shadowserver found over 115,000 exposed Fireboxes at the time, with nearly 9,000 still unpatched after nine months. CISA added the flaw to its Known Exploited Vulnerabilities catalog in December under BOD 22-01 and on Thursday confirmed ransomware gangs are now exploiting it, without providing campaign details. WatchGuard serves more than 250,000 small and mid-sized companies through 17,000+ security resellers and service providers.

ZDI-26-632: WatchGuard FireWare OS epm connect Stack-based Buffer Overflow Remote Code Execution Vulnerability

ZDI disclosed a CVSS 8.8 unauthenticated stack-based buffer overflow in WatchGuard FireWare OS epm connect enabling network-adjacent remote code execution.

ZDI published advisory ZDI-26-632 for a stack-based buffer overflow in the epm connect component of WatchGuard FireWare OS. Network-adjacent attackers can execute arbitrary code without authentication. ZDI assigned CVSS 8.8 and the issue is tracked as CVE-2026-13086.

ZDI Published Advisoriesupdated · 5d agofirst · 6d agoAdvisory 2 sourcesCVE-2026-13086

WatchGuard security advisory (AV26-865)

Canada's Cyber Centre warns WatchGuard Dimension and Fireware OS vulnerabilities affect multiple versions and urges administrators to apply available updates.

The Canadian Centre for Cyber Security issued advisory AV26-865 (August 31, 2026) noting that WatchGuard products are affected by vulnerabilities as of August 27, 2026. Affected products include Dimension prior to 2.3.1 and Fireware OS prior to 12.12.2, 12.5.20, and 2026.2.2. Users and administrators are encouraged to review the advisory link and apply updates as they become available.

Canadian Centre for Cyber Security · 15d agoAdvisory

Related CVEs

  • Out-of-Bounds Write in WatchGuard Fireware OS iked Enables Unauthenticated RCE
    WatchGuard Fireware OS contains an out-of-bounds write (CWE-787) in the iked process that a remote, unauthenticated attacker can trigger to execute arbitrary code on the appliance. The flaw is reachable via the mobile user VPN with IKEv2 and via branch office VPNs using IKEv2 to a dynamic gateway peer; devices whose IKEv2 configurations were deleted may remain vulnerable if a branch office VPN to a static gateway peer is still configured. Successful exploitation yields full system compromise, reflected in the CVSS v4.0 base score of 9.3 (network vector, no privileges or user interaction, high impact on confidentiality, integrity and availability). WatchGuard Firebox appliances with IKEv2 VPN services are affected, with public reporting citing roughly 54,000 internet-exposed Fireboxes; the issue was added to CISA's Known Exploited Vulnerabilities catalog on 2025-11-12, a public proof-of-concept exploit exists, and headlines indicate use in ransomware attacks (KEV ransomware field is listed as unknown). EPSS assigns a 91.3% probability of exploitation within 30 days (100th percentile), so remediation urgency is high.
    · WatchGuard Firebox appliances running Fireware OS (iked process) KEV PoC large
  • Unauthenticated Out-of-Bounds Write RCE in WatchGuard Fireware OS
    CVE-2025-14733 is an out-of-bounds write (CWE-787) in the iked process of WatchGuard Fireware OS on Firebox appliances, allowing a remote, unauthenticated attacker to execute arbitrary code. The flaw is reachable when the appliance is configured for Mobile User VPN with IKEv2 or a branch office VPN (BOVPN) using IKEv2 with a dynamic gateway peer; a Firebox may also remain vulnerable if those IKEv2 configurations were previously set up and then deleted while a BOVPN to a static gateway peer is still configured. Successful exploitation gives an attacker arbitrary code execution on the firewall itself, a high-value network position that can be used for further lateral movement. Affected deployments are WatchGuard Firebox appliances running Fireware OS with the described IKEv2 VPN configurations, since the IKEv2 service by definition listens on the external interface. The vulnerability is under active exploitation: it was added to CISA's KEV catalog on 2025-12-19 with known ransomware use, carries an EPSS probability of 26.5% (98th percentile) of exploitation within 30 days, and no public proof-of-concept is currently known.
    · WatchGuard Firebox (Fireware OS) KEV ransomwarelarge
  • Privilege Escalation in WatchGuard Firebox/XTM Fireware OS
    WatchGuard Firebox and XTM appliances running affected versions of Fireware OS contain a privilege escalation flaw that allows a remote attacker who already holds unprivileged credentials to obtain a privileged management session via exposed management access. The flaw is triggered when management access is exposed (for example, to the internet) and an attacker authenticates with low-privileged credentials, at which point they can elevate to privileged management of the appliance. Because the CVSS v3.1 score of 8.8 carries high confidentiality, integrity, and availability impact, full compromise of the appliance is the realistic outcome. Organizations running Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U3, or 12.2.x through 12.5.x before 12.5.7_U3 are affected. The vulnerability is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-04-11, and the Russia-linked Cyclops Blink botnet used it as an initial access vector to infect thousands of devices before the FBI disrupted the botnet.
    · WatchGuard Firebox and XTM appliances (Fireware OS) Fireware OS before 12.7.2_U1; 12.x before 12.1.3_U3; 12.2.x through 12.5.x before 12.5.7_U3 KEVmass
  • Unauthenticated Stack Buffer Overflow RCE in WatchGuard Fireware OS epm Service
    CVE-2026-13086 is a stack-based buffer overflow (CWE-121, CWE-787) in the epm (Endpoint Protection Manager) service of WatchGuard Fireware OS, tied to the now-deprecated Mobile Security feature; the advisory also associates CWE-798 (hard-coded credentials) with the finding. An unauthenticated remote attacker can trigger the overflow via the epm service (per ZDI-26-632, through a 'connect' request), gaining the ability to execute arbitrary code with the privileges of that service on the Firebox appliance. Impact is rated critical (CVSS 4.0: 9.3), with network attack vector, no privileges or user interaction required, and high loss of confidentiality, integrity, and availability on the compromised system. Affected organizations are WatchGuard Firebox users whose Fireware OS still exposes the deprecated Mobile Security (epm) component; deployments that have disabled or removed that feature are not exposed to this service. No public proof-of-concept is known, the flaw is not yet in CISA KEV, and EPSS currently assigns a low 0.4% probability of exploitation within 30 days, though the ZDI advisory makes the issue publicly disclosed.
    · WatchGuard Fireware OS (epm / Endpoint Protection Manager service, deprecated Mobile Security feature)moderate

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.