WatchGuard Firebox (Fireware OS) LDAP-Injection-Schwachstelle CVE-2026-1498

Hat jemand WatchGuard Firebox Firewalls im Einsatz? In diversen Versionen des Fireware OS gibt es eine kritische LDAP-Injection-Schwachstelle CVE-2026-1498, die zeitnah gepatcht werden sollte.

Borns IT- und Windows-Blog

Can anyone provide me the latest #Watchguard #Firebox T40 firmware?

Looks like it can only be downloaded from customers with an account, no?

#firewall #fedihelp

New critical WatchGuard Firebox firewall flaw exploited in attacks

WatchGuard has warned customers to patch a critical, actively exploited remote code execution (RCE) vulnerability in its Firebox firewalls.

BleepingComputer
🚨 CRITICAL zero-day in WatchGuard Firebox (Fireware OS iked process): unauthenticated RCE exploited in the wild. Patch immediately, restrict VPN access, monitor iked activity. CVE: N/A https://radar.offseq.com/threat/watchguard-patches-firebox-zero-day-exploited-in-t-8e6753b5 #OffSeq #Firebox #ZeroDay #Cybersecurity
WatchGuard warnt: Kritische Firebox‑Lücke wird aktiv angegriffen. Eine schwerwiegende Schwachstelle in WatchGuard‑Firebox‑Systemen wird derzeit aktiv ausgenutzt. Die Lücke (CVE‑2025‑14733, CVSS 9.3) betrifft den VPN‑Dienst der Geräte und ermöglicht Angreifern, über präparierte Anfragen tief in das System einzudringen. #CyberSecurity #WatchGuard #Firebox #ITSecurity

admin:admin
user:user
admin:readwrite
...
Wenn schon: admin:R34dWr1t3  

#Watchguard #Firebox: Gefährdung durch Standardpasswort für Admin | Security https://www.heise.de/news/Watchguard-Firebox-Gefaehrdung-durch-Standardpasswort-fuer-Admin-11072045.html #WatchguardFirebox

Watchguard Firebox: Gefährdung durch Standardpasswort für Admin

Watchguard versieht die Firebox-Firewalls mit Standardpasswörtern. Angreifer können sich dadurch leicht Admin-Rechte verschaffen.

heise online
📢 76 000 pare-feux WatchGuard Firebox exposés à une vulnérabilité critique RCE (CVE-2025-9242)
📝 Selon un extrait d’actualité publié le 20.10.2025, près de 76 000 app...
📖 cyberveille : https://cyberveille.ch/posts/2025-10-23-76-000-pare-feux-watchguard-firebox-exposes-a-une-vulnerabilite-critique-rce-cve-2025-9242/
🌐 source : https://www.bleepingcomputer.com/news/security/over-75-000-watchguard-security-devices-vulnerable-to-critical-rce/
#CVE_2025_9242 #Firebox #Cyberveille
76 000 pare-feux WatchGuard Firebox exposés à une vulnérabilité critique RCE (CVE-2025-9242)

Selon un extrait d’actualité publié le 20.10.2025, près de 76 000 appliances WatchGuard Firebox exposées sur Internet restent vulnérables à une faille critique (CVE-2025-9242) permettant à un attaquant distant d’exécuter du code sans authentification. Points clés: Produits concernés: WatchGuard Firebox (appliances de sécurité réseau) Vulnérabilité: CVE-2025-9242 (criticité élevée) Impact: Exécution de code à distance sans authentification (RCE) Exposition: ~76 000 appareils visibles sur le web public Tactiques/Techniques (TTPs): Exécution de code à distance (RCE) sans authentification par un attaquant distant Il s’agit d’une brève de vulnérabilité visant à signaler l’ampleur de l’exposition et la gravité du risque identifié.

CyberVeille

A critical flaw in WatchGuard Firebox devices leaves over 75,000 systems wide open to remote attacks—could your network be next? Discover the high-stakes vulnerability and why urgent patching matters.

https://thedefendopsdiaries.com/cve-2025-9242-critical-watchguard-firebox-vulnerability-exposes-over-75000-devices-worldwide/

#cve20259242
#watchguard
#firebox
#remotecodeexecution
#networksecurity

Update now: #WatchGuard urges users to update Firebox firewalls to fix a critical 9.3-rated flaw that could let remote attackers run code without authentication.

Read: https://hackread.com/watchguard-fix-for-firebox-firewall-vulnerability/

#CyberSecurity #Firebox #Firewall #Vulnerability

WatchGuard Issues Fix for 9.3-Rated Firebox Firewall Vulnerability

Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread

Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto
🔴 WatchGuard Firebox firewalls face a CRITICAL vulnerability (no CVE yet). No public exploits, but risk to enterprise networks is high. Restrict admin access & monitor logs. Patch ASAP when available. More: https://radar.offseq.com/threat/watchguard-warns-of-critical-vulnerability-in-fire-523a02d1 #OffSeq #Firebox #Vulnerability #Cybersecurity