Skip to main content
Reconnecting to live updates…

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

0
Critical
Vulnerabilityrceransomware
Published: 09/10/2026 (09/10/2026, 09:10:20 UTC)
Source: Bleeping Computer

Description

A critical remote code execution (RCE) vulnerability in WatchGuard Firebox firewalls (CVE-2025-14733) is actively exploited by ransomware gangs. The flaw allows unauthenticated attackers to execute malicious code remotely via an out-of-bounds write. It affects Fireware OS versions 11.x and later, 12.x and later, and 2025.1 through 2025.1.3. Despite patches released in December 2025, many devices remain unpatched and exposed online. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation and included this vulnerability in its Known Exploited Vulnerabilities catalog, mandating urgent patching for federal agencies. WatchGuard has provided indicators of compromise to assist detection. The vulnerability is particularly risky when IKEv2 VPN is configured, but residual risk remains if certain VPN configurations persist.

Affected software

Affected versions
>=11.0.0>=12.0.0>=2025.1 <=2025.1.3

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 09:22:31 UTC

Technical Analysis

CVE-2025-14733 is a critical remote code execution vulnerability in WatchGuard Firebox firewalls caused by an out-of-bounds write that allows unauthenticated attackers to execute code remotely with low complexity. It affects Fireware OS 11.x and later (including 11.12.4_Update1), 12.x and later (including 12.11.5), and versions 2025.1 through 2025.1.3. WatchGuard released patches in December 2025, noting that unpatched devices are vulnerable primarily if configured to use IKEv2 VPN, though some risk remains if branch office VPNs to static gateway peers are configured. CISA confirmed active exploitation by ransomware groups and added the flaw to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch within a week. Shadowserver reported over 115,000 unpatched devices exposed online in December 2025, with nearly 9,000 still vulnerable nine months later. This vulnerability follows a pattern of WatchGuard firewall flaws actively exploited in the wild.

Potential Impact

The vulnerability enables unauthenticated remote attackers to execute arbitrary code on affected WatchGuard Firebox firewalls, potentially leading to full compromise of the device. This has been actively exploited by ransomware gangs, increasing the risk of ransomware deployment and network disruption. The exposure of a large number of unpatched devices online amplifies the threat. The impact is significant for organizations using vulnerable Firebox firewalls, especially those with IKEv2 VPN configurations or residual VPN settings. Successful exploitation can undermine network security and facilitate ransomware attacks.

Mitigation Recommendations

WatchGuard released official patches for CVE-2025-14733 in December 2025. Organizations should apply these patches immediately to affected Fireware OS versions. WatchGuard has also provided indicators of compromise to help detect exploitation. CISA has mandated patching for federal agencies and included this vulnerability in its Known Exploited Vulnerabilities catalog. If patching is not immediately possible, organizations should review and disable vulnerable VPN configurations, particularly IKEv2 VPN and branch office VPNs to static gateway peers, to reduce exposure. Continuous monitoring for signs of compromise using provided indicators is recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.67,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks/","fetched":true,"fetchedAt":"2026-09-10T09:22:22.154Z","wordCount":656}

Threat ID: 6aa276ceacd9273b49d8d7e7

Added to database: 09/10/2026, 09:22:22 UTC

Last enriched: 09/10/2026, 09:22:31 UTC

Last updated: 09/10/2026, 14:48:40 UTC

Views: 60

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses