LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
cve recordhighexploited in the wild3 of 3 cataloguesexploit reported

CVE-2022-23176

WatchGuard · Firebox and XTM · WatchGuard Firebox and XTM Privilege Escalation Vulnerability

· Added to CISA KEV
CVSS
Severityhigh
Weakness
EPSS12.7%96.0th percentile
Exploited3 KEV sources
Ransomware useUnknown
Federal fix dueMay 2, 2022
patch window

Called exploited 21 days after disclosure.

Measured from the CVE publication date to the earliest of 3 KEV catalogues that list it.

The life of this vulnerability

  1. CVE published
  2. First KEV listing21d
  3. Last KEV listing25d
  4. Last sighting10mo

Gaps are compressed to equal steps. The elapsed time is printed under each.

Which catalogues call it exploited

Sources3 of 3
Listings differ by25 d
Strongest claimconfirmed

3 catalogues list it. CIRCL aggregates the others and is shown but not counted.

Public exploitation evidence

4 public reports collected from VulnCheck and CIRCL, first on Mar 17, 2022. Each links to its original source. We have not verified them.

Description

WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access.

Required action (CISA)

Apply updates per vendor instructions.

References

← Back to the CVE Tracker

Our coverage of CVE-2022-23176

CVE-2025-14733critical

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

Ransomware groups are actively exploiting a critical vulnerability in WatchGuard Firebox firewalls, according to CISA. The flaw, tracked as CVE-2025-14733, allows unauthenticated attackers to execute remote code with low complexity. While WatchGuard released patches in December, a significant number of devices remain vulnerable, with thousands still exposed online.