CISA: WatchGuard RCE flaw now exploited in ransomware attacks
A critical remote code execution (RCE) vulnerability in WatchGuard Firebox firewalls (CVE-2025-14733) is actively exploited by ransomware gangs. The flaw allows unauthenticated attackers to execute malicious code remotely via an out-of-bounds write. It affects Fireware OS versions 11.x and later, 12.x and later, and 2025.1 through 2025.1.3. Despite patches released in December 2025, many devices remain unpatched and exposed online. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation and included this vulnerability in its Known Exploited Vulnerabilities catalog, mandating urgent patching for federal agencies. WatchGuard has provided indicators of compromise to assist detection. The vulnerability is particularly risky when IKEv2 VPN is configured, but residual risk remains if certain VPN configurations persist.
AI Analysis
Technical Summary
CVE-2025-14733 is a critical remote code execution vulnerability in WatchGuard Firebox firewalls caused by an out-of-bounds write that allows unauthenticated attackers to execute code remotely with low complexity. It affects Fireware OS 11.x and later (including 11.12.4_Update1), 12.x and later (including 12.11.5), and versions 2025.1 through 2025.1.3. WatchGuard released patches in December 2025, noting that unpatched devices are vulnerable primarily if configured to use IKEv2 VPN, though some risk remains if branch office VPNs to static gateway peers are configured. CISA confirmed active exploitation by ransomware groups and added the flaw to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch within a week. Shadowserver reported over 115,000 unpatched devices exposed online in December 2025, with nearly 9,000 still vulnerable nine months later. This vulnerability follows a pattern of WatchGuard firewall flaws actively exploited in the wild.
Potential Impact
The vulnerability enables unauthenticated remote attackers to execute arbitrary code on affected WatchGuard Firebox firewalls, potentially leading to full compromise of the device. This has been actively exploited by ransomware gangs, increasing the risk of ransomware deployment and network disruption. The exposure of a large number of unpatched devices online amplifies the threat. The impact is significant for organizations using vulnerable Firebox firewalls, especially those with IKEv2 VPN configurations or residual VPN settings. Successful exploitation can undermine network security and facilitate ransomware attacks.
Mitigation Recommendations
WatchGuard released official patches for CVE-2025-14733 in December 2025. Organizations should apply these patches immediately to affected Fireware OS versions. WatchGuard has also provided indicators of compromise to help detect exploitation. CISA has mandated patching for federal agencies and included this vulnerability in its Known Exploited Vulnerabilities catalog. If patching is not immediately possible, organizations should review and disable vulnerable VPN configurations, particularly IKEv2 VPN and branch office VPNs to static gateway peers, to reduce exposure. Continuous monitoring for signs of compromise using provided indicators is recommended.
CISA: WatchGuard RCE flaw now exploited in ransomware attacks
Description
A critical remote code execution (RCE) vulnerability in WatchGuard Firebox firewalls (CVE-2025-14733) is actively exploited by ransomware gangs. The flaw allows unauthenticated attackers to execute malicious code remotely via an out-of-bounds write. It affects Fireware OS versions 11.x and later, 12.x and later, and 2025.1 through 2025.1.3. Despite patches released in December 2025, many devices remain unpatched and exposed online. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation and included this vulnerability in its Known Exploited Vulnerabilities catalog, mandating urgent patching for federal agencies. WatchGuard has provided indicators of compromise to assist detection. The vulnerability is particularly risky when IKEv2 VPN is configured, but residual risk remains if certain VPN configurations persist.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-14733 is a critical remote code execution vulnerability in WatchGuard Firebox firewalls caused by an out-of-bounds write that allows unauthenticated attackers to execute code remotely with low complexity. It affects Fireware OS 11.x and later (including 11.12.4_Update1), 12.x and later (including 12.11.5), and versions 2025.1 through 2025.1.3. WatchGuard released patches in December 2025, noting that unpatched devices are vulnerable primarily if configured to use IKEv2 VPN, though some risk remains if branch office VPNs to static gateway peers are configured. CISA confirmed active exploitation by ransomware groups and added the flaw to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch within a week. Shadowserver reported over 115,000 unpatched devices exposed online in December 2025, with nearly 9,000 still vulnerable nine months later. This vulnerability follows a pattern of WatchGuard firewall flaws actively exploited in the wild.
Potential Impact
The vulnerability enables unauthenticated remote attackers to execute arbitrary code on affected WatchGuard Firebox firewalls, potentially leading to full compromise of the device. This has been actively exploited by ransomware gangs, increasing the risk of ransomware deployment and network disruption. The exposure of a large number of unpatched devices online amplifies the threat. The impact is significant for organizations using vulnerable Firebox firewalls, especially those with IKEv2 VPN configurations or residual VPN settings. Successful exploitation can undermine network security and facilitate ransomware attacks.
Mitigation Recommendations
WatchGuard released official patches for CVE-2025-14733 in December 2025. Organizations should apply these patches immediately to affected Fireware OS versions. WatchGuard has also provided indicators of compromise to help detect exploitation. CISA has mandated patching for federal agencies and included this vulnerability in its Known Exploited Vulnerabilities catalog. If patching is not immediately possible, organizations should review and disable vulnerable VPN configurations, particularly IKEv2 VPN and branch office VPNs to static gateway peers, to reduce exposure. Continuous monitoring for signs of compromise using provided indicators is recommended.
Technical Details
- Classification
- {"confidence":0.67,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks/","fetched":true,"fetchedAt":"2026-09-10T09:22:22.154Z","wordCount":656}
Threat ID: 6aa276ceacd9273b49d8d7e7
Added to database: 09/10/2026, 09:22:22 UTC
Last enriched: 09/10/2026, 09:22:31 UTC
Last updated: 09/10/2026, 14:48:40 UTC
Views: 60
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.