WatchGuard Firebox OS forced to patch worrying security flaw, so update now

  • WatchGuard patches critical RCE flaw (CVE‑2025‑14733) in Firebox firewalls, being actively exploited in the wild
  • CISA added it to KEV; federal agencies must patch or stop use by December 26
  • Workarounds include disabling dynamic peer BOVPNs and tightening firewall policies until fixes are applied

WatchGuard has patched a critical-severity zero-day vulnerability in its Firebox firewalls, and urged all users to apply the fix immediately.

In a new security advisory, the company said firewalls running Fireware OS 11.x and later, 12.x and later, and 2025.1 up to (and including) 2025.1.3, contained an out-of-bounds write vulnerability that allowed unauthenticated attackers to execute arbitrary code, remotely (RCE). This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.

The flaw is now tracked as CVE-2025-14733, and was given a severity score of 9.3/10 (critical). WatchGuard said it has seen threat actors “actively attempting to exploit” the vulnerability in the wild, but did not discuss which groups were using it, or against whom.

CISA adds the bug to KEV

Those that cannot apply the fix immediately can work around the issue by disabling dynamic peer BOVPNs, adding new firewall policies, and disabling the default system policies that handle VPN traffic.

At the same time, the US Cybersecurity and Infrastructure Security Agency (CISA) added the RCE flaw to its Known Exploited Vulnerabilities (KEV) catalog, giving all Federal Civilian Executive Branch (FCEB) agencies just a one-week deadline to patch up or stop using vulnerable Firebox firewalls entirely.

The entry was added on December 19, with the due date being December 26.

A few months ago, WatchGuard patched a similar RCE bug in its Firebox firewalls, BleepingComputer reported. In October 2025, internet watchdog Shadowserver said there were more than 75,000 exposed instances, with the majority being located in North America, and Europe. This vulnerability, too, was added to CISA’s KEV a few weeks later.

WatchGuard Technologies is a global cybersecurity company that serves more than 250,000 customers worldwide across small and midsize enterprises, MSPs, and other organizations.

Via BleepingComputer

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

Siri won’t be your AI girlfriend

‘Listen, that's not what I'm here for, right?' | Image: Apple Our early testing has already shown that Siri AI knows when to shut up,...

Amazon’s Echo Hub gets a customizable new look and Ring’s AI features

Amazon's rolling out a free software update for Echo Hub devices that gives the home screen a much-needed update to the interface it launched...

Telegram brings back its Wear OS app after five years with chats, voice messages, more

Five years after killing its Wear OS app, Telegram is reviving support for Android smartwatches with its latest update. Read more @ 9to5google

Waze now shows traffic lights on your route, but it’s rolling out slowly

In testing for several months now, Waze is starting to roll out traffic lights more widely in navigation, but it’s still not available to...

Here are the price-matching policies for Best Buy, GameStop, and others

Nothing is more frustrating than buying a new pair of headphones, an OLED TV, or a laptop just to find out that you could...

The bill that would let Jimmy Kimmel sue Brendan Carr is here

Under a new bipartisan bill, Americans could sue for damages if a government official illegally tries to coerce a social media, AI, or broadcasting...

Amazon’s data centers used 2.5 billion gallons of water last year

Just after Seattle enacted a one-year data center moratorium that some of Amazon's own employees pushed for, Amazon shared how much water its data...

Roborock’s Q10 S5 Plus robovac is over half off, matching its best price to date

Roborock’s Q10 S5 Plus comes with a self-emptying dock and is under $300. | Image: Roborock Even at full price, the Roborock Q10 S5 Plus...

Blink’s six-piece outdoor camera kit is a great deal under $200

You can save on a big set of outdoor security cameras ahead of Prime Day. Amazon has a five-pack of Blink cameras with a...

Logitech’s awesome MX Master 3S mouse drops to under $100

The platform-agnostic Logitech MX Master 3S wireless mouse is discounted to $89.99 at Amazon ($30 off), matching the best price we’ve seen so far...