{"record":"WatchGuard evidence record","url":"https://nexalign.io/vendors/watchguard","vendor":{"slug":"watchguard","name":"WatchGuard","domain":"watchguard.com","category":"network","categoryLabel":"Network security"},"lastChecked":"2026-07-18T04:17:27.246Z","coverage":{"earliest":"2022-03-25T00:00:00.000Z","latest":"2026-07-18T04:17:27.246Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":66,"kindsOfSource":5,"attributedAdvisories":58,"knownExploited":4,"registerEntriesNotAttributable":0,"practitionerThreads":1,"independentItems":3,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":42,"latest":"2026-07-02T23:08:27.000Z"},{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":14,"latest":"2026-07-03T10:50:50.911Z"},{"source":"Known Exploited Vulnerabilities catalogue","operator":"CISA, United States","classification":"authoritative","items":4,"latest":"2025-12-19T00:00:00.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":3,"latest":"2026-07-18T04:17:27.246Z"},{"source":"Practitioner discussions","operator":"Reddit, public threads","classification":"independent","items":3,"latest":"2026-01-29T17:29:39.000Z"}],"advisories":{"shown":6,"total":58,"truncated":true,"fullList":"https://nexalign.io/vendors/watchguard/advisories","items":[{"id":"CVE-2025-14733","description":"WatchGuard Firebox Out of Bounds Write Vulnerability","severity":"critical","cvss":9.3,"knownExploited":true,"date":"2025-12-19T00:01:55.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-204437","https://nvd.nist.gov/vuln/detail/CVE-2025-14733"]},{"id":"CVE-2025-9242","description":"WatchGuard Firebox Out-of-Bounds Write Vulnerability","severity":"critical","cvss":9.3,"knownExploited":true,"date":"2025-11-12T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-9242","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-29699"]},{"id":"CVE-2022-23176","description":"WatchGuard Firebox and XTM Privilege Escalation Vulnerability","severity":"critical","cvss":null,"knownExploited":true,"date":"2022-04-11T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2022-23176"]},{"id":"CVE-2022-26318","description":"WatchGuard Firebox and XTM Appliances Arbitrary Code Execution","severity":"critical","cvss":null,"knownExploited":true,"date":"2022-03-25T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2022-26318"]},{"id":"WID-SEC-2026-2193","description":"Affected products: WatchGuard Firebox","severity":"high","cvss":8.1,"knownExploited":false,"date":"2026-07-03T10:50:50.911Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2193"]},{"id":"CVE-2026-13053","description":"An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command.","severity":"high","cvss":8.6,"knownExploited":false,"date":"2026-07-02T23:08:27.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41463"]}]},"practitionerThreads":{"shown":1,"total":1,"truncated":false,"items":[{"title":"Watchguards turn, WatchGuard Warns of Active Exploitation of Critical Fireware OS VPN Vulnerability","context":"r/msp","url":"https://www.reddit.com/r/msp/comments/1pqxwia/watchguards_turn_watchguard_warns_of_active/","date":"2025-12-19T22:11:45.000Z"}]},"independentCoverage":{"shown":3,"total":3,"truncated":false,"items":[{"title":"WatchGuard - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/WatchGuard","date":null},{"title":"WatchGuard Firebox Reviews, Competitors and Pricing","host":"peerspot.com","url":"https://www.peerspot.com/products/watchguard-firebox-reviews","date":null},{"title":"What is your primary use case for WatchGuard Firebox?","host":"peerspot.com","url":"https://www.peerspot.com/questions/what-is-your-primary-use-case-for-watchguard-firebox","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}