• News/
  • https://www.theregister.com/2025/12/19/watchguard_firebox/

WatchGuard sounds alarm as critical Firebox flaw comes under active attack

The Register
·
Carly Page
·
Published Dec 19, 2025
·
Updated

WatchGuard is in emergency patch mode after confirming that a critical remote code execution flaw in its Firebox firewalls is under active attack. In an advisory published this week, the network security vendor warned customers that attackers are exploiting CVE-2025-32978, a 9.3-rated vulnerability affecting Firebox firewalls. The bug allows unauthenticated attackers to execute arbitrary commands remotely, effectively handing over control of the firewall if the device is reachable over the internet. WatchGuard said the bug resides in the Fireware OS Internet Key Exchange (IKE) service and can be exploited remotely, without authentication, to execute arbitrary code on vulnerable Firebox devices. The vendor confirmed it has seen the flaw actively exploited in the wild and has released indicators of compromise to help customers assess whether they've been hit. "This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer," WatchGuard said in a Thursday advisory. "If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured." The immediate fix is to apply the latest firmware updates, which WatchGuard says fully address the vulnerability. For organizations unabl...

Read full article

Affected Software

1 affected component
WatchGuard Firebox
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical remote code execution vulnerability in WatchGuard's Firebox firewalls that is currently being exploited.

2

What security implications are discussed?

The article highlights the immediate threat posed by an active attack on the critical flaw, urging users to apply emergency patches.

3

What products or software are affected?

The affected product is the WatchGuard Firebox firewall.

4

What action is WatchGuard taking in response to the vulnerability?

WatchGuard is in emergency patch mode to address the critical flaw and protect its customers.

5

How can users protect themselves from the reported vulnerability?

Users are advised to urgently apply the security patches provided by WatchGuard to their Firebox firewalls.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203