Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
WatchGuard Technologies

WatchGuard Technologies Vendor Cyber Rating & Cyber Score

watchguard.com

WatchGuard® Technologies, Inc. is a global leader in unified cybersecurity. Our Unified Security Platform® approach is uniquely designed for managed service providers to deliver world-class security that increases their business scale and velocity while also improving operational efficiency. Trusted by more than 17,000 security resellers and service providers to protect more than 250,000 customers, the company’s award-winning products and services span network security and intelligence, advanced endpoint protection, multi-factor authentication, and secure Wi-Fi. Together, they offer five critical elements of a security platform: comprehensive security, shared knowledge, clarity & control, operational alignment, and automation. The company


WatchGuard Technologies A.I CyberSecurity Scoring

WatchGuard Technologies
Company Information
Website:https://www.watchguard.com/
Employees number:1,201
Number of followers:70,544
NAICS:541514
Industry Type:Computer and Network Security
Homepage:watchguard.com
WatchGuard Technologies Risk Score (AI oriented)
Between 750 and 799
logo
WatchGuard TechnologiesComputer and Network Security
Updated:
28/03/2026
750/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
WatchGuard Technologies Global Score (TPRM)
xxxx
logo
WatchGuard TechnologiesComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

WatchGuard Technologies
WatchGuard TechnologiesFair
Current Score
750Baa (FAIR)
01000
4 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
752Before Incident
MAY 2026
751Before Incident
APRIL 2026
751Before Incident
MARCH 2026
750Before Incident
FEBRUARY 2026
750Before Incident
JANUARY 2026
749Before Incident
DECEMBER 2025
754Before Incident
Vulnerability
18 Dec 2025WatchGuard Technologies
WatchGuard: WatchGuard Warns of Active Exploitation of Critical Fireware OS VPN Vulnerability

Critical Security Flaw in WatchGuard Fireware OS (CVE-2025-14733) Exploited in the Wild

749After Incident
CRITICAL-5
WAT1766159772
WatchGuard Patches Actively Exploited Critical Fireware OS Vulnerability (CVE-2025-14733) WatchGuard has released emergency patches for a critical security flaw in Fireware OS (CVE-2025-14733, CVSS 9.3) that has been exploited in real-world attacks. The vulnerability, an out-of-bounds write in the iked process, allows remote unauthenticated attackers to execute arbitrary code on affected systems. The flaw impacts Fireware OS configurations using IKEv2 for mobile user VPNs or branch office VPNs (BOVPNs) with dynamic gateway peers. Even if these configurations were later deleted, devices may remain vulnerable if a BOVPN with a static gateway peer is still active. Affected versions include: - 2025.1 (fixed in 2025.1.4) - 12.x (fixed in 12.11.6) - 12.5.x (T15 & T35 models) (fixed in 12.5.15) - 12.3.1 (FIPS-certified) (fixed in 12.3.1_Update4) - 11.x (11.10.2–11.12.4_Update1) (end-of-life, no patch available) WatchGuard confirmed active exploitation attempts, with attacks traced to the IP address 199.247.7[.]82—the same address linked to recent Fortinet FortiOS vulnerabilities (CVE-2025-59718, CVE-2025-59719). Indicators of compromise (IoCs) include: - Logs showing rejected IKE2 certificate chains exceeding 8 certificates. - IKE_AUTH requests with abnormally large CERT payloads (>2000 bytes). - iked process crashes or hangs, disrupting VPN connections. This disclosure follows CISA’s addition of another critical WatchGuard flaw (CVE-2025-9242, CVSS 9.3) to its Known Exploited Vulnerabilities (KEV) catalog last month, though no direct link between the two campaigns has been established. As a temporary mitigation, administrators can disable dynamic peer BOVPNs, restrict access to static IP peers via firewall policies, and disable default VPN traffic policies. Patches should be applied immediately to mitigate risk.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Systems Affected: WatchGuard Firebox devices running vulnerable Fireware OS versionsDowntime: VPN connections interrupted during exploit; iked process crashOperational Impact: VPN service disruption, potential arbitrary code executionBrand Reputation Impact: Potential reputational damage due to active exploitation
NOVEMBER 2025
753Before Incident
OCTOBER 2025
757Before Incident
SEPTEMBER 2025
757Before Incident
AUGUST 2025
757Before Incident
JULY 2025
752Before Incident
JUNE 2025
756Before Incident
Vulnerability
16 Jun 2025WatchGuard Technologies
WatchGuard Technologies

Critical Vulnerability (CVE-2025-9242) in WatchGuard Firebox Appliances Exposes 76,000 Devices

751After Incident
CRITICAL-5
WAT5192051102025
A critical vulnerability (CVE-2025-9242, CVSS 9.3) in WatchGuard Firebox network security appliances exposes 75,835+ devices globally, primarily in the U.S., Germany, and Europe. The flaw—an out-of-bounds write in the Fireware OS ‘iked’ process—allows unauthenticated remote code execution via malicious IKEv2 VPN packets. Affected versions (11.10.2–11.12.4_Update1, 12.0–12.11.3, 2025.1) lack patches unless upgraded to 2025.1.1, 12.11.4, or 12.5.13. End-of-life 11.x versions remain permanently vulnerable. While no active exploitation is confirmed, the flaw enables attackers to bypass authentication, execute arbitrary code, and potentially compromise internal networks protected by these appliances. Organizations relying on Firebox for VPN gateways, traffic filtering, or cloud security face heightened risk of lateral movement, data exfiltration, or full system takeover if unpatched. Shadowserver Foundation’s scans confirm the exposure is not honeypots, urging immediate patching or mitigation via IPSec/IKEv2 hardening for static gateways.
INCIDENT DETAILS -
TYPE
Vulnerability ExposureUnauthenticated Remote Code Execution (RCE)
IMPACT
Systems Affected: 75,835 WatchGuard Firebox appliances (as of latest scan)Operational Impact: Potential unauthorized remote code execution, compromise of network traffic, and bypass of security controlsBrand Reputation Impact: High (due to widespread exposure of critical security appliances)
JUNE 2025
761Before Incident
Vulnerability
01 Jun 2025WatchGuard Technologies
WatchGuard and NCP Engineering: WatchGuard VPN Client for Windows Vulnerability Enables Command Execution With SYSTEM Privileges

WatchGuard Patches Critical Privilege-Escalation Flaw in Mobile VPN IPSec Client for Windows

756After Incident
HIGH-5
WATNCP1770302039
WatchGuard Patches Critical Privilege-Escalation Flaw in Mobile VPN IPSec Client for Windows WatchGuard has issued a security advisory addressing a significant privilege-escalation vulnerability (WGSA-2026-00002 / NCPVE-2025-0626) in its Mobile VPN with IPSec client for Windows, which could allow local attackers to execute arbitrary commands with SYSTEM-level privileges. The flaw stems from underlying software technology provided by NCP Engineering and affects the installation management process, enabling attackers to bypass administrative protections. The vulnerability manifests during installation, updates, or uninstallation of the software, where the MSI installer launches command-line windows (cmd.exe) running under the SYSTEM account the highest privilege level in Windows. On older Windows versions, these command prompts are interactive, allowing attackers to interrupt the process, interact with the open prompt, and execute malicious commands with inherited SYSTEM rights. While the CVSS score is 6.3 (Medium), the impact metrics rate Confidentiality, Integrity, and Availability as High, indicating a full system compromise if exploited. The flaw affects WatchGuard Mobile VPN with IPSec client versions up to and including 15.19. No workarounds exist, and remediation requires upgrading to version 15.33 or higher, which modifies installer behavior to prevent exposure of elevated command prompts. Organizations using legacy Windows systems are at heightened risk due to the interactive nature of the vulnerability. WatchGuard and NCP Engineering have released the patch to address the issue.
INCIDENT DETAILS -
TYPE
Privilege Escalation
IMPACT
Systems Affected: Windows systems with WatchGuard Mobile VPN with IPSec clientOperational Impact: Full system compromise possible
JUNE 2022
758Before Incident
Vulnerability
16 Jun 2022WatchGuard Technologies
WatchGuard Technologies

WatchGuard Firebox Firewalls Remote Code Execution Vulnerability (CVE-2025-9242)

757After Incident
MEDIUM-1
WAT0970609100325
WatchGuard disclosed CVE-2025-9242, a critical remote code execution (RCE) vulnerability in its Firebox firewalls due to an out-of-bounds write flaw in the iked process (IKEv2 VPN component). The vulnerability allows unauthenticated attackers to execute arbitrary code on affected devices, even if previously vulnerable configurations (mobile user VPN or dynamic gateway peer BOVPN) were deleted—if a static gateway peer BOVPN remains active. The flaw impacts Fireware OS 11.x (EOL), 12.x, and 2025.1, with patches released in versions 12.3.1_Update3, 12.5.13, 12.11.4, and 2025.1.1. Over 250,000 SMBs using WatchGuard’s firewalls (models: T15 to M690, Firebox Cloud, FireboxV, etc.) are at risk. While no active exploitation is reported, the vulnerability poses a severe threat, as firewalls are prime targets for ransomware groups (e.g., Akira exploiting SonicWall’s CVE-2024-40766). CISA previously mandated patches for a similar WatchGuard flaw (2022) exploited in attacks. Unpatched systems risk full device compromise, enabling lateral movement, data exfiltration, or ransomware deployment. WatchGuard provided a temporary workaround (disabling dynamic BOVPNs, modifying firewall policies) but urges immediate patching to prevent potential supply-chain attacks or mass exploitation by threat actors.
INCIDENT DETAILS -
TYPE
VulnerabilityRemote Code Execution (RCE)
IMPACT
Firebox T15, T35 (Fireware OS 12.5.x)Vulnerable if configured with IKEv2 VPNFirebox T20, T25, T40, T45, T55, T70, T80, T85, M270, M290, M370, M390, M470, M570, M590, M670, M690, M440, M4600, M4800, M5600, M5800 (Fireware OS 12.x)Vulnerable if configured with IKEv2 VPNFirebox Cloud, Firebox NV5, FireboxV (Fireware OS 12.x)Vulnerable if configured with IKEv2 VPNFirebox T115-W, T125, T125-W, T145, T145-W, T185 (Fireware OS 2025.1.x)Vulnerable if configured with IKEv2 VPNPotential unauthorized remote code executionRisk of firewall compromisePotential reputational damage if exploited

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for WatchGuard Technologies ?
?
What was WatchGuard Technologies's A.I Rankiteo Cyber Score in May 2026 ?
?
What was WatchGuard Technologies's A.I Rankiteo Cyber Score in April 2026 ?
?
What was WatchGuard Technologies's A.I Rankiteo Cyber Score in March 2026 ?
?
What was WatchGuard Technologies's A.I Rankiteo Cyber Score in February 2026 ?
?
What was WatchGuard Technologies's A.I Rankiteo Cyber Score in January 2026 ?
?
What was WatchGuard Technologies's A.I Rankiteo Cyber Score in December 2025 ?
?
What was WatchGuard Technologies's A.I Rankiteo Cyber Score in November 2025 ?
?
What was WatchGuard Technologies's A.I Rankiteo Cyber Score in October 2025 ?
?
What was WatchGuard Technologies's A.I Rankiteo Cyber Score in September 2025 ?
?
What was WatchGuard Technologies's A.I Rankiteo Cyber Score in August 2025 ?
?
What was WatchGuard Technologies's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on WatchGuard Technologies's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with WatchGuard Technologies ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view WatchGuard Technologies's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
WatchGuard Technologies Cyber Scoring History | Rankiteo