CISA Warns: WatchGuard RCE Flaw Exploited in Ransomware Attacks

www.news4hackers.com-cisa-warns-watchguard-rce-flaw-exploited-in-ransomware-attacks-cisa-warns-watchguard-rce-flaw-exploited-in-ransomware-attacks

Security agencies and vendors are urging urgent action as a critical vulnerability in WatchGuard Firebox firewalls is being exploited by ransomware groups.

CISA’s Response and Urgent Actions

CISA has reported that ransomware groups are leveraging a critical vulnerability in WatchGuard Firebox firewalls. The flaw, designated CVE-2025-14733, allows unauthenticated attackers to execute arbitrary code remotely through an out-of-bounds write vulnerability. This issue impacts Fireware OS versions 11.x (including 11.12.4_Update1), 12.x (including 12.11.5), and 2025.1 through 2025.1.3.

Impact on WatchGuard Firebox Users

WatchGuard initially disclosed the patch for this flaw in December, noting that unpatched systems remain at risk if configured to use IKEv2 VPN. The company also warned that even if vulnerable configurations are removed, devices connected to a static gateway peer via branch office VPNs could still be compromised.

Shadowserver’s Findings

Security researchers at Shadowserver identified over 115,000 unpatched Firebox firewalls exposed online in December, with nearly 9,000 still vulnerable after nine months. CISA recently updated its catalog of actively exploited vulnerabilities to include CVE-2025-14733, confirming its use in ransomware campaigns without disclosing specific attack details.

Prior Incidents and Patch History

The agency first listed the flaw in its Known Exploited Vulnerabilities (KEV) catalog in December, mandating U.S. federal agencies to address the issue within a week under Binding Operational Directive 22-01. This follows a prior incident in which CISA required urgent remediation for another WatchGuard vulnerability, CVE-2022-23176, affecting Firebox and XTM firewalls.

New Patch and Exploitation Timeline

In September 2025, WatchGuard released a patch for a separate remote code execution flaw, CVE-2025-9242, which shared similarities with CVE-2025-14733. A month after the fix, CISA classified the vulnerability as actively exploited, coinciding with Shadowserver’s discovery of over 75,000 exposed Firebox devices.

Broader Security Implications

WatchGuard serves more than 250,000 small and mid-sized businesses through a global network of 17,000 resellers and service providers. Additional insights into threat actor behavior are highlighted in The Blue Report 2026, which analyzed 338 million security simulations across customer environments. The study revealed that 37% of attacker activities are blocked when valid credentials are compromised.

Other Recent Vulnerabilities

CISA has also addressed other recent vulnerabilities, including a critical remote code execution flaw in Windows IKE Extension and exploits targeting Langflow, N-central, and Apache Tomcat. The agency continues to emphasize urgent remediation for actively exploited issues, such as the recent Citrix NetScaler RCE flaw and a Microsoft SharePoint vulnerability linked to ransomware attacks.

Recommendations for Organizations

The report underscores the persistent threat landscape, with attackers increasingly targeting network infrastructure to bypass security measures. Organizations are advised to prioritize patching and monitor for indicators of compromise associated with CVE-2025-14733.

CISA has reported that ransomware groups are leveraging a critical vulnerability in WatchGuard Firebox firewalls. The flaw, designated CVE-2025-14733, allows unauthenticated attackers to execute arbitrary code remotely through an out-of-bounds write vulnerability.



About Author

en_USEnglish