WatchGuard Fireware OS in focus: ZDI discloses new pre-auth RCE (CVE-2026-13086) as CISA confirms ransomware exploiting CVE-2025-14733
Two distinct unauthenticated remote code execution flaws in WatchGuard's Fireware OS are in the news this week: on 2026-09-09 ZDI disclosed a network-adjacent stack-based buffer overflow in the epm connect component (ZDI-26-632, CVE-2026-13086, CVSS 8.8), and…
The reports cover two separate vulnerabilities in WatchGuard's firewall operating system, which ZDI spells 'FireWare OS' and BleepingComputer spells 'Fireware OS'; they should not be conflated. (1) On 2026-09-09, ZDI published advisory ZDI-26-632 for a stack-based buffer overflow in the epm connect component of WatchGuard FireWare OS. Network-adjacent attackers can execute arbitrary code without authentication; ZDI assigned CVSS 8.8 and the issue is tracked as CVE-2026-13086. (2) Separately, per BleepingComputer (2026-09-10), CISA confirmed on Thursday that ransomware gangs are now exploiting CVE-2025-14733, an out-of-bounds write in WatchGuard Fireware OS enabling unauthenticated remote code execution on firewalls configured for IKEv2 VPN, and potentially even after that configuration was deleted if a static branch-office VPN peer remains. WatchGuard released patches in December and confirmed in-the-wild exploitation; CISA had added the flaw to its Known Exploited Vulnerabilities catalog in December under BOD 22-01, ordering federal patching within a week. CISA provided no campaign details. When the flaw was disclosed, Shadowserver found over 115,000 exposed Fireboxes; after nine months nearly 9,000 remain unpatched. BleepingComputer notes WatchGuard serves more than 250,000 small and mid-sized companies through 17,000+ security resellers and service providers, and that WatchGuard published IOCs to check for compromise. The BleepingComputer report's CVE list also references CVE-2022-23176 and CVE-2025-9242, but the provided summary gives no details about them. No CVSS score is stated for CVE-2025-14733 in these reports (BleepingComputer's tldr characterizes it as critical); no exploit code was provided in either report.
- ZDI advisory ZDI-26-632 (published 2026-09-09): stack-based buffer overflow in the epm connect component of WatchGuard FireWare OS, tracked as CVE-2026-13086, rated CVSS 8.8 by ZDI.
- CVE-2026-13086 allows unauthenticated, network-adjacent remote code execution.
- CVE-2025-14733 is an out-of-bounds write in WatchGuard Fireware OS enabling unauthenticated remote code execution on Fireboxes configured for IKEv2 VPN.
- CVE-2025-14733 may remain exploitable even after the IKEv2 configuration was deleted if a static branch-office VPN peer remains.
- CISA added CVE-2025-14733 to its KEV catalog in December (the report gives no year; the 'nine months' figure is consistent with December 2025) under BOD 22-01, ordering federal patching within a week.
- On Thursday (report dated 2026-09-10), CISA confirmed ransomware gangs are exploiting CVE-2025-14733, without providing campaign details.
- WatchGuard released patches for CVE-2025-14733 in December, confirmed in-the-wild exploitation, and published IOCs to check for compromise.
- Shadowserver found over 115,000 exposed Fireboxes in December; nearly 9,000 remain unpatched after nine months.
Coverage timelineoldest first · each row is one article
- · 6d agoZDI-26-632: WatchGuard FireWare OS epm connect Stack-based Buffer Overflow Remote Code Execution Vulnerability
ZDI Published Advisories· 35
ZDI disclosed a CVSS 8.8 unauthenticated stack-based buffer overflow in WatchGuard FireWare OS epm connect enabling network-adjacent remote code execution.
- · 5d agoCISA: WatchGuard RCE flaw now exploited in ransomware attacks
BleepingComputer· 80
CISA confirms ransomware gangs are exploiting critical unauthenticated RCE CVE-2025-14733 in WatchGuard Firebox firewalls, with roughly 9,000 devices still unpatched.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-23176 | Privilege Escalation in WatchGuard Firebox/XTM Fireware OS WatchGuard Firebox and XTM appliances running affected versions of Fireware OS contain a privilege escalation flaw that allows a remote attacker who already holds unprivileged credentials to obtain a privileged management session via exposed management access. The flaw is triggered when management access is exposed (for example, to the internet) and an attacker authenticates with low-privileged credentials, at which point they can elevate to privileged management of the appliance. Because the CVSS v3.1 score of 8.8 carries high confidentiality, integrity, and availability impact, full compromise of the appliance is the realistic outcome. Organizations running Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U3, or 12.2.x through 12.5.x before 12.5.7_U3 are affected. The vulnerability is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-04-11, and the Russia-linked Cyclops Blink botnet used it as an initial access vector to infect thousands of devices before the FBI disrupted the botnet. Do: Upgrade affected Fireware OS branches to 12.7.2_U1, 12.1.3_U3, or 12.5.7_U3 (or later) per WatchGuard's instructions, as required by CISA's KEV catalog. Until patched, restrict appliance management access to trusted networks or management VPNs rather than exposing it to the internet. Because this flaw was used to deploy the Cyclops Blink botnet, administrators should also check Firebox/XTM devices for signs of that compromise using vendor detection guidance. | 8.8 | 13% | KEV |
| masson the order of 100,000+ potentially exposed Firebox/XTM appliances (WatchGuard's installed base is cited in the millions, with management access commonly… | |
| CVE-2025-14733 | Unauthenticated Out-of-Bounds Write RCE in WatchGuard Fireware OS CVE-2025-14733 is an out-of-bounds write (CWE-787) in the iked process of WatchGuard Fireware OS on Firebox appliances, allowing a remote, unauthenticated attacker to execute arbitrary code. The flaw is reachable when the appliance is configured for Mobile User VPN with IKEv2 or a branch office VPN (BOVPN) using IKEv2 with a dynamic gateway peer; a Firebox may also remain vulnerable if those IKEv2 configurations were previously set up and then deleted while a BOVPN to a static gateway peer is still configured. Successful exploitation gives an attacker arbitrary code execution on the firewall itself, a high-value network position that can be used for further lateral movement. Affected deployments are WatchGuard Firebox appliances running Fireware OS with the described IKEv2 VPN configurations, since the IKEv2 service by definition listens on the external interface. The vulnerability is under active exploitation: it was added to CISA's KEV catalog on 2025-12-19 with known ransomware use, carries an EPSS probability of 26.5% (98th percentile) of exploitation within 30 days, and no public proof-of-concept is currently known. Do: Upgrade affected Firebox appliances to the patched Fireware OS builds identified in WatchGuard's security advisory, per CISA KEV required action and applicable BOD 22-01 guidance. Audit configurations for Mobile User VPN with IKEv2 and BOVPN IKEv2 with a dynamic gateway peer, including appliances where those settings were deleted but a BOVPN to a static gateway peer is still configured, as these may remain vulnerable. Until patched, restrict IKEv2 traffic (UDP 500/4500) to trusted source addresses or discontinue use if mitigations are unavailable. | 9.3 | 27% | KEV ransomware |
| largeplausibly in the tens of thousands of internet-exposed Firebox appliances (order of magnitude 10^4 to 10^5); unknown precisely | |
| CVE-2025-9242 | Out-of-Bounds Write in WatchGuard Fireware OS iked Enables Unauthenticated RCE WatchGuard Fireware OS contains an out-of-bounds write (CWE-787) in the iked process that a remote, unauthenticated attacker can trigger to execute arbitrary code on the appliance. The flaw is reachable via the mobile user VPN with IKEv2 and via branch office VPNs using IKEv2 to a dynamic gateway peer; devices whose IKEv2 configurations were deleted may remain vulnerable if a branch office VPN to a static gateway peer is still configured. Successful exploitation yields full system compromise, reflected in the CVSS v4.0 base score of 9.3 (network vector, no privileges or user interaction, high impact on confidentiality, integrity and availability). WatchGuard Firebox appliances with IKEv2 VPN services are affected, with public reporting citing roughly 54,000 internet-exposed Fireboxes; the issue was added to CISA's Known Exploited Vulnerabilities catalog on 2025-11-12, a public proof-of-concept exploit exists, and headlines indicate use in ransomware attacks (KEV ransomware field is listed as unknown). EPSS assigns a 91.3% probability of exploitation within 30 days (100th percentile), so remediation urgency is high. Do: Apply the patched Fireware OS release per WatchGuard's security advisory immediately (exact fixed version numbers are not provided in the source data); the KEV listing makes BOD 22-01 remediation timelines mandatory for U.S. federal agencies. As an interim mitigation, restrict or disable IKEv2 VPN exposure — mobile user VPN with IKEv2 and branch office VPN IKEv2, including residual static-peer BOVPN configurations on devices that previously had IKEv2 configured — to trusted sources only. Administrators should audit configuration history to identify Fireboxes with prior IKEv2 mobile VPN or dynamic-peer BOVPN setups, since these may remain vulnerable even after the configs were deleted. | 9.3 | 91% | KEV PoC |
| large≈54,000 internet-exposed Fireboxes (public scan figure cited in coverage) | |
| CVE-2026-13086 | Unauthenticated Stack Buffer Overflow RCE in WatchGuard Fireware OS epm Service CVE-2026-13086 is a stack-based buffer overflow (CWE-121, CWE-787) in the epm (Endpoint Protection Manager) service of WatchGuard Fireware OS, tied to the now-deprecated Mobile Security feature; the advisory also associates CWE-798 (hard-coded credentials) with the finding. An unauthenticated remote attacker can trigger the overflow via the epm service (per ZDI-26-632, through a 'connect' request), gaining the ability to execute arbitrary code with the privileges of that service on the Firebox appliance. Impact is rated critical (CVSS 4.0: 9.3), with network attack vector, no privileges or user interaction required, and high loss of confidentiality, integrity, and availability on the compromised system. Affected organizations are WatchGuard Firebox users whose Fireware OS still exposes the deprecated Mobile Security (epm) component; deployments that have disabled or removed that feature are not exposed to this service. No public proof-of-concept is known, the flaw is not yet in CISA KEV, and EPSS currently assigns a low 0.4% probability of exploitation within 30 days, though the ZDI advisory makes the issue publicly disclosed. Do: Check whether Mobile Security/epm is enabled on your Fireboxes and whether the epm service is reachable from untrusted networks (management or external interfaces), and restrict access to it via firewall policy until patched. Apply the Fireware OS fix referenced in WatchGuard's advisory/ZDI-26-632 for your appliance's version line once confirmed, since specific fixed version numbers were not included in this data. Monitor WatchGuard's security portal for updates, as public disclosure via ZDI increases the likelihood of exploit development. | 9.3 | <1% |
| moderatelikely on the order of thousands to low tens of thousands of Firebox appliances with the deprecated Mobile Security (epm) service exposed (subset of… |