A Critical WatchGuard Flaw Now Being Exploited by Ransomware Gangs
The US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs have started using a previously identified vulnerability in WatchGuard Firebox firewalls to carry out attacks. This critical flaw, tracked as CVE-2025-14733, was first flagged by CISA in December 2025 and allows unauthenticated threat actors to execute malicious code remotely with low complexity.
The vulnerability affects Fireware OS versions 11.x and later, including the most recent release (11.12.4_Update1), as well as versions 12.x or later (including 12.11.5) and 2025.1 through 2025.1.3. According to WatchGuard, unpatched Firebox firewalls are only vulnerable if configured to use IKEv2 VPN, but even in cases where the vulnerable configurations have been deleted, branch office VPNs to static gateway peers can still pose a risk.
WatchGuard’s own research has shown that attackers were exploiting this flaw in the wild as early as December 2025. The company provided indicators of compromise (IoCs) to help its customers check whether their Firebox devices had been compromised. Internet security watchdog group Shadowserver found over 115,000 unpatched Firebox firewalls exposed online at the time, and nearly 9,000 instances remain unsecured even after nine months.
CISA has now added CVE-2025-14733 to its catalog of actively exploited vulnerabilities, following a previous directive in December that ordered US federal agencies to secure their systems within a week. This move comes as no surprise given CISA’s track record on addressing similar WatchGuard flaws in the past. In September 2025, the agency tagged another RCE vulnerability (CVE-2025-9242) affecting Firebox firewalls as actively exploited, just months after WatchGuard had patched it.
The impact of this flaw is significant, particularly given its use by ransomware gangs. According to a recent report from Blue Report, only 37% of actions taken by attackers with valid credentials are blocked once they have gained access to a system. This highlights the importance of patching vulnerabilities as soon as possible and maintaining robust security measures.
For small and mid-sized businesses that rely on WatchGuard services – over 250,000 companies worldwide use its products through a network of more than 17,000 security resellers and service providers – this development is particularly concerning. CISA’s confirmation that ransomware gangs are now exploiting CVE-2025-14733 serves as a stark reminder of the need for vigilance in maintaining the security posture of networks and systems.
To mitigate the risk posed by this flaw, it is essential to apply the latest patches as soon as possible and review current configurations to ensure they do not pose an additional vulnerability. Additionally, regular monitoring and incident response planning can help organizations detect and respond to potential breaches more effectively.
Source: Bleeping Computer — 2026-09-10