Vulnerability Management, Patch/Configuration Management

Attacks involving critical WatchGuard Firebox bug ongoing, CISA warns

binary code and magnifying glass

Malicious actors were noted by the Cybersecurity and Infrastructure Security Agency to have been abusing the critical WatchGuard Firebox bug, tracked as CVE-2025-9242, prompting its inclusion in the agency's Known Exploited Vulnerabilities catalog, reports The Hacker News.

Federal agencies have been urged to address the vulnerability by Dec. 3. Intrusions involving the out-of-bounds write flaw in Fireware OS noted by watchTowr Labs researchers to have stemmed from an inadequate identification buffer length check during the IKE handshake process continue to threaten potential arbitrary code execution in over 54,300 Firebox appliances, data from the Shadowserver Foundation revealed.

The U.S. accounted for most of the vulnerable devices, followed by Italy, the UK, Germany, and Canada. Other flaws added to the CISA's KEV list include the high-severity Windows kernel defect, tracked as CVE-2025-62215, and the critical Gladinet Triofox improper access control issue, tracked as CVE-2025-12480, with the latter reported to have been leveraged in UNC6485 attacks.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds