CISA: WatchGuard RCE flaw now exploited in ransomware attacks

The US Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm on a critical vulnerability in WatchGuard Firebox firewalls that’s being exploited by ransomware gangs. This flaw, tracked as CVE-2025-14733, allows unauthenticated attackers to remotely execute malicious code with ease, putting countless organizations at risk.

The vulnerability affects firewalls running Fireware OS 11.x and later, including the most recent versions 11.12.4_Update1, 12.x or later (including 12.11.5), and 2025.1 through 2025.1.3. This means that even if a company has updated its firewall in recent months, it may still be vulnerable to attacks. WatchGuard’s own security patches released in December were meant to plug this hole, but the company warned at the time that unpatched firewalls could still be compromised – even after deleting vulnerable configurations.

What makes this vulnerability particularly concerning is that over 115,000 Firebox devices were found exposed online back in December by Internet security watchdog group Shadowserver. And despite WatchGuard’s efforts to mitigate the issue, nearly 9,000 of those unsecured instances remain online today, nine months later. This is a stark reminder that even with robust cybersecurity measures in place, human error and outdated systems can still lead to devastating consequences.

CISA first flagged this vulnerability as actively exploited in December, when it added CVE-2025-14733 to its Known Exploited Vulnerabilities (KEV) catalog. The agency ordered US federal agencies to patch their systems within a week, as mandated by Binding Operational Directive (BOD) 22-01. This is not the first time CISA has sounded the alarm on WatchGuard vulnerabilities – just last year, it warned about another actively exploited flaw affecting Firebox and XTM firewalls.

The fact that ransomware gangs are now exploiting this vulnerability only serves to underscore the importance of prompt patching and vigilance in cybersecurity. WatchGuard’s services support over 250,000 small and mid-sized companies worldwide through a network of more than 17,000 security resellers and service providers. It’s clear that even with robust defenses in place, organizations can still be caught off guard by these types of vulnerabilities.

So what can you do to protect your organization? First and foremost, ensure that all Firebox devices are updated to the latest software versions. Additionally, be on high alert for suspicious activity – if you suspect that your system has been compromised, take immediate action to contain the damage. And remember: prevention is just one aspect of a robust cybersecurity strategy; regular monitoring and incident response plans can help minimize the impact of attacks like these.

In an era where ransomware gangs are becoming increasingly sophisticated in their tactics, it’s more crucial than ever that organizations stay on top of vulnerabilities like this one. Don’t wait until it’s too late – take proactive steps to protect your network today.


Source: Bleeping Computer — 2026-09-10