The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has warned government agencies to patch an actively exploited vulnerability impacting WatchGuard Firebox firewalls. Remote attackers can use this critical security flaw (CVE-2025-9242) to execute malicious code remotely on vulnerable devices by exploiting an out-of-bounds write weakness in firewalls running Fireware OS 11.x (end of life), 12.x, and 2025.1. CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog and has given Federal Civilian Executive Branch (FCEB) agencies three weeks, until December 3, to secure their systems against ongoing attacks as mandated by the Binding Operational Directive (BOD) 22-01. "These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," the cybersecurity agency said. "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable." While WatchGuard released security patches to address the vulnerability on September 17, the company only tagged it as exploited in attacks almost one month later, on October 21. One day earlier, on October 20, Internet watchdog Shadowserver revealed that it was tracking over 75,000 vulnerable Firebox appliances worldwide. This number has fallen to just over 54,000, according to Shadowserver's latest statistics, most of them located in Europ...
CISA warns of WatchGuard firewall flaw exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Nov 13, 2025
·Updated
Affected Software
3 affected components
WatchGuard Firebox=11.x
WatchGuard Firebox=12.x
WatchGuard Firebox=2025.1
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical vulnerability in WatchGuard Firebox firewalls that is being actively exploited by attackers.
2
What security implications are discussed in the article?
The article highlights that remote attackers can exploit the vulnerability to compromise systems and networks using WatchGuard Firebox firewalls.
3
What versions of WatchGuard Firebox are affected by the vulnerability?
The vulnerability affects WatchGuard Firebox versions 11.x, 12.x, and 2025.1.
4
What action does CISA recommend for agencies using affected products?
CISA recommends that agencies promptly apply patches to their affected WatchGuard Firebox firewalls to mitigate the risk.
5
Who issued the warning about the WatchGuard firewall flaw?
The warning about the WatchGuard firewall flaw was issued by the U.S. Cybersecurity & Infrastructure Security Agency (CISA).