CISA Confirms Ransomware Exploitation of WatchGuard Firebox RCE Flaw


CISA via GitHub
government
CISA Catalog of Known Exploited Vulnerabilities
“The CVE-2025-14733 entry lists WatchGuard Firebox, remote-code-execution impact, IKEv2 exposure, required mitigation and knownRansomwareCampaignUse as Known.”
BleepingComputer
news
CISA: WatchGuard RCE flaw now exploited in ransomware attacks
“CISA confirmed ransomware gangs are exploiting the WatchGuard Firebox vulnerability, and the report lists affected Fireware OS versions and remaining exposed instances.”
Shield53 Threat Wire
news
WatchGuard CVE-2025-14733: 9,000 Unpatched Firewalls Now Ransomware Targets
“The analysis emphasizes perimeter-firewall compromise, residual IKEv2/BOVPN exposure, credential rotation and assume-breach response.”
Ransomware use
CISA now lists CVE-2025-14733 as having known ransomware campaign use.
IKEv2 exposure
The flaw affects Firebox systems using IKEv2-related VPN configurations, including specific Mobile User VPN and Branch Office VPN scenarios.
Patch lag
Nearly 9,000 vulnerable Firebox instances reportedly remained exposed about nine months after earlier disclosure activity.
CISA has confirmed that ransomware actors are exploiting CVE-2025-14733, a critical remote-code-execution vulnerability in WatchGuard Firebox appliances running multiple Fireware OS versions. The update underscores how firewall and VPN flaws can remain durable entry points months after disclosure.1
The agency’s Known Exploited Vulnerabilities catalog now lists the WatchGuard Firebox flaw as having “Known” ransomware campaign use. CISA says internet-accessible instances should be checked for signs of compromise after mitigations are applied.1
The September 10, 2026, update changes the defender calculus. Affected organizations should treat exposed Firebox systems as possible footholds, not merely as devices awaiting routine maintenance.
CVE-2025-14733 affects the Fireware OS iked process and may allow a remote, unauthenticated attacker to execute arbitrary code. CISA says exposure applies to Mobile User VPN with IKEv2 and Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.1 BleepingComputer reported that affected Fireware OS versions include 11.x and later, 12.x and later, and 2025.1 through 2025.1.3.2
The primary risk is not every Firebox deployment equally, but Firebox appliances with IKEv2-related VPN exposure. WatchGuard previously said unpatched devices were vulnerable when configured to use IKEv2 VPN. BleepingComputer also reported a residual-risk condition: systems may remain exposed even after vulnerable settings are removed if a branch office VPN to a static gateway peer is still configured.2
That detail matters for security operations teams because configuration history can complicate asset triage. A firewall that no longer appears to have the original vulnerable configuration may still warrant review if BOVPN settings, static gateway peers or internet-facing IKEv2 services remain present.
Threat-intelligence summaries published after CISA’s update also emphasized IKEv2 and BOVPN mitigation, monitoring and SOC triage as immediate priorities.5
Shadowserver data cited by BleepingComputer showed that more than 115,000 unpatched Firebox firewalls were exposed online in December, while nearly 9,000 remained unsecured after nine months.2 Shield53 likewise framed the issue as a continuing risk for small and midsize businesses and managed service providers, warning that perimeter-firewall compromise can give ransomware crews a path around endpoint-focused controls.3
Firewalls and VPN appliances sit at the boundary between the internet and internal networks. When attackers compromise them, they may gain a foothold before traffic reaches systems monitored by conventional endpoint tooling. They may also obtain access to VPN paths, routing context, credentials, logs or administrative interfaces that help them move laterally.
The WatchGuard case fits a broader ransomware pattern. Attackers continue to revisit edge-device vulnerabilities long after vendors publish fixes, relying on patch lag, incomplete asset inventories and complex appliance configurations.
HackWire’s contextual report described compromised firewalls as high-value ransomware footholds and urged defenders to audit management exposure and managed-service patch posture.6 The Axe Report’s September 10 roundup placed the WatchGuard issue among other edge and infrastructure risks, reinforcing the operational problem of exploitable device populations persisting after disclosure.8
For MSPs, the exposure is especially consequential. BleepingComputer noted that WatchGuard serves more than 250,000 small and midsize companies through more than 17,000 security resellers and service providers worldwide.2 A vulnerable perimeter appliance in that ecosystem can represent not only one organization’s remote-access risk, but also a potential operational blind spot across many customer environments.
CISA’s required action is to apply vendor mitigations, follow applicable federal guidance or discontinue use if mitigations are unavailable.1 For private-sector defenders, the practical equivalent is to identify all Firebox appliances, confirm Fireware versions, determine whether IKEv2 or BOVPN configurations are present, and validate that fixes or mitigations are applied.
But because CISA now links the flaw to ransomware activity, response should include a compromise assessment. CISA’s note specifically calls for checking internet-accessible instances for signs of potential compromise after mitigation.1 WatchGuard has also shared indicators of compromise to help customers determine whether Firebox devices were hacked, according to BleepingComputer.2
Security teams should preserve relevant evidence before making disruptive changes where feasible. That includes configuration exports, logs, VPN settings, admin-account state and network-flow data. Cyber Decision Ledger’s response record recommends containment, evidence preservation, validated patching, credential rotation and clean rebuild or replacement when Firebox compromise cannot be excluded.4
Organizations running WatchGuard Firebox appliances should prioritize the following actions:
The key distinction is sequencing. Teams should not wait for a full investigation before applying urgent mitigations. But they also should not assume that applying an update erases attacker access. If a perimeter firewall was reachable while vulnerable, defenders should validate both the fix and the integrity of the device and associated credentials.
CVE-2025-14733 was added to CISA’s KEV catalog on December 19, 2025, with a federal remediation due date of December 26, 2025.1 The September 10, 2026, ransomware-use update shows that exploitation risk did not end with the original deadline.
For security operations teams, the lesson is direct: firewall and VPN vulnerabilities need post-patch validation, configuration-specific exposure analysis and incident-response checks.
In the WatchGuard case, the most important question is no longer only whether a Firebox has been patched. It is whether the appliance was exposed long enough to become part of a ransomware intrusion path.

Apple’s first foldable iPhone is not just a hardware catch-up to Android rivals. Its larger test is whether iOS 27.1 can make a 7.6-inch folding screen feel like a flexible mobile workspace without turning the device into a small iPad.

ETH Zurich’s Swiss National Supercomputing Centre will host Switzerland’s first IBM Quantum System Two, giving Swiss researchers and selected companies a dedicated route into IBM’s Nighthawk-based hardware. The near-term value will depend less on headline qubit counts than on how users combine quantum circuits with classical supercomputing workflows.

CoreWeave’s new Physical AI Field Engineering service embeds domain specialists with enterprise engineering teams to turn proprietary test, simulation and telemetry data into production AI. The offering is credible where customers need help operationalizing models against real-world physics, but it also deepens CoreWeave’s role as a high-touch services layer around its AI cloud infrastructure.

IBM and NASA released an open-source lunar foundation model trained on multimodal Moon observations, aiming to help researchers map ice prospects, craters and volcanic features. The release also exposes the central question for scientific AI: whether open weights, data and benchmarks are enough to make model outputs reproducible and useful for mission planning.
CVE-2025-14733
A WatchGuard Firebox out-of-bounds write vulnerability in Fireware OS that can allow unauthenticated remote-code execution under certain VPN configurations.
IKEv2
A VPN protocol commonly used to establish encrypted tunnels for remote users or site-to-site connectivity.
BOVPN
Branch Office VPN, a site-to-site VPN configuration used to connect networks across locations.
KEV catalog
CISA’s Known Exploited Vulnerabilities catalog, which tracks vulnerabilities confirmed to be exploited in the wild and assigns remediation expectations for federal agencies.
The Axe Report
The Example Key From the Setup Guide (09/10/2026)
Comments