EXPOSURES › CVE-2022-26318
CVE-2022-26318
HIGH ⌖ ON CISA KEV · EXPLOITEDUnauthenticated remote code execution vulnerability in WatchGuard Firebox and XTM appliances.
An unauthenticated user can execute arbitrary code on WatchGuard Firebox and XTM appliances, enabling attackers to compromise network security. DIB organizations must ensure these appliances are patched immediately to prevent remote code execution and potential data breaches. This failure highlights the critical need for timely patch management of network security hardware.
Shame score — An unauthenticated remote code execution vulnerability in a widely deployed network security appliance is a severe, avoidable failure that directly compromises organizational security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code.