Skip to content
COOEY

FAIL › dossier

WatchGuard

VENDOR

· dossier confidence 50%

WatchGuard Firebox appliances have repeatedly demonstrated critical vulnerabilities allowing remote code execution and privileged access, indicating a need for improved security practices and patching processes. These failures highlight potential risks for DIB/CMMC compliance.

PROFILE
CategorycybersecurityWhat they doWatchGuard provides network security solutions, including firewalls, threat management, and cloud security services. They offer a range of products designed to protect businesses from cyber threats.
SECURITY POSTURE

WatchGuard Firebox appliances have a history of high-severity remote code execution vulnerabilities, often exploitable by unauthenticated attackers. Remediation efforts include implementing security awareness and training, and improving security posture and processes.

Notable failures
  • CVE-2025-14733 (RCE)
  • CVE-2025-9242 (RCE)
  • CVE-2022-26318 (RCE)
  • CVE-2022-23176 (Privileged Access)
Patterns: repeated unpatched RCE vulnerabilities; unauthenticated access exploitation; exposed management access
FAILURE HISTORY · 8
DATEEVENTSEVSUMMARY
2022-04-11 CVE-2022-23176 high WatchGuard Firebox and XTM appliances allow remote attackers with unprivileged credentials to escalate to privileged management sessions via exposed management access.
2022-03-25 CVE-2022-26318 high Unauthenticated remote code execution vulnerability in WatchGuard Firebox and XTM appliances.
2025-12-19 CVE-2025-14733 high WatchGuard Firebox suffered an unpatched OOBW vulnerability allowing remote code execution through the IKEv2 VPN process.
2025-11-12 CVE-2025-9242 high WatchGuard Firebox OS iked process allowed remote unauthenticated attackers to execute arbitrary code
2025-12-19 CVE-2025-14733 critical CVE-2025-14733: An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process
2025-09-17 CVE-2025-9242 critical CVE-2025-9242: An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process
2024-09-25 CVE-2024-6593 critical CVE-2024-6593: Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka
2024-09-25 CVE-2024-6592 critical CVE-2024-6592: An incorrect authorization vulnerability in the protocol communication between t
Open questions: What is WatchGuard's current patching cadence? · What specific security awareness and training programs are in place? · What is WatchGuard's ownership structure?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-28 12:50:00.945240+00:00