WatchGuard Firebox's IKEv2 VPN Bug Hit Twice, and One Is Tied to Ransomware
Two nearly identical out-of-bounds write vulnerabilities in Firebox's iked process, both CVSS 9.8, both unauthenticated remote code execution, one confirmed for ransomware.
Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.
Two nearly identical out-of-bounds write vulnerabilities in Firebox's iked process, both CVSS 9.8, both unauthenticated remote code execution, one confirmed for ransomware.
An additional pair of GitLab server-side request forgery vulnerabilities, distinct from the CVE covered earlier in this series, both confirmed exploited within weeks of each other.
A perfect-10 code execution bug in AEM Forms and a 9.1 session-takeover flaw in Commerce and Magento both entered CISA's KEV catalogue within days of each other in October 2025.
A heap overflow first exploited in 2009, a use-after-free from 2020, and a fresh prototype pollution bug — all three confirmed exploited against Adobe Acrobat and Reader within weeks of each other.
Array Networks' ArrayOS AG command injection and Motex LANSCOPE's communication-channel verification flaw are unrelated products that share the same structural weakness: infrastructure built to be trusted rather than to verify.
CVE-2025-15556 let an attacker who intercepts update traffic serve a malicious installer that Notepad++'s WinGUp updater would execute unverified — in one of the most widely installed Windows utilities.
CVE-2026-22769's hardcoded credential in Dell RecoverPoint for VMs was already being exploited by a tracked threat group, UNC6201, before Dell shipped a fix.
CVE-2026-34197 turns ActiveMQ's Jolokia JMX-HTTP bridge into a code execution chain, exploiting an ordering flaw where Spring instantiates beans before the broker validates configuration.
CVE-2023-27351 in PaperCut's SecurityRequestFilter class bypasses authentication with no credentials at all, and CISA flags it with a confirmed ransomware association.
Weekly insights on software supply chain security, delivered to your inbox.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.