Malicious actors were noted by the Cybersecurity and Infrastructure Security Agency to have been abusing the critical WatchGuard Firebox bug, tracked as CVE-2025-9242, prompting its inclusion in the agency's Known Exploited Vulnerabilities catalog, reports The Hacker News.Federal agencies have been urged to address the vulnerability by Dec. 3. Intrusions involving the out-of-bounds write flaw in Fireware OS noted by watchTowr Labs researchers to have stemmed from an inadequate identification buffer length check during the IKE handshake process continue to threaten potential arbitrary code execution in over 54,300 Firebox appliances, data from the Shadowserver Foundation revealed.The U.S. accounted for most of the vulnerable devices, followed by Italy, the UK, Germany, and Canada. Other flaws added to the CISA's KEV list include the high-severity Windows kernel defect, tracked as CVE-2025-62215, and the critical Gladinet Triofox improper access control issue, tracked as CVE-2025-12480, with the latter reported to have been leveraged in UNC6485 attacks.
Vulnerability Management, Patch/Configuration Management
Attacks involving critical WatchGuard Firebox bug ongoing, CISA warns

(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



