LmCast :: Stay tuned in

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

Recorded: Sept. 10, 2026, 10:01 a.m.

Original Summarized

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

News

Featured
Latest

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Over 36,000 exposed Plex servers vulnerable to recent flaws

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

Microsoft fixes bug that wiped Windows desktop settings

Trezor warns users of email provider breach, phishing attacks

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityCISA: WatchGuard RCE flaw now exploited in ransomware attacks

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

By Sergiu Gatlan

September 10, 2026
05:10 AM
0

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December.
This flaw is tracked as CVE-2025-14733 and stems from an out-of-bounds write allowing unauthenticated threat actors to execute malicious code remotely in low-complexity attacks.
This vulnerability affects firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and 2025.1 through 2025.1.3.
When it released CVE-2025-14733 security patches in December, WatchGuard said unpatched Firebox firewalls are vulnerable to attacks only if configured to use IKEv2 VPN, but noted they might still be compromised even if the vulnerable configurations have been deleted if a branch office VPN to a static gateway peer is still configured.
WatchGuard also confirmed that attackers were exploiting the flaw in the wild and shared indicators of compromise to help customers check whether their Firebox devices have been hacked.
Internet security watchdog group Shadowserver found over 115,00 unpatched Firebox firewalls exposed online in December, and nearly 9,000 instances remain unsecured after nine months.

Vulnerable WatchGuard firewalls exposed online (Shadowserver)
In a Thursday update to its catalog of actively exploited vulnerabilities, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said the CVE-2025-14733 flaw is now known to be used by ransomware gangs but has not provided more details about their attacks.
CISA first added the flaw to its Known Exploited Vulnerabilities (KEV) catalog in December, when it ordered U.S. federal agencies to secure their systems within a week, as mandated by Binding Operational Directive (BOD) 22-01.
Two years ago, the cybersecurity agency ordered government agencies to patch another actively exploited WatchGuard flaw (CVE-2022-23176) affecting Firebox and XTM firewalls.
More recently, in September 2025, WatchGuard patched an RCE vulnerability (CVE-2025-9242) affecting Firebox firewalls and almost identical to CVE-2025-14733. One month later, CISA tagged the flaw as actively exploited, and Shadowserver found more than 75,000 Firebox firewalls vulnerable to attacks.
WatchGuard provides services to more than 250,000 small and mid-sized companies through a network of more than 17,000 security resellers and service providers worldwide.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report

Related Articles:
CISA: Microsoft SharePoint flaw now exploited in ransomware attacksCISA orders feds to patch Citrix NetScaler RCE flaw by SaturdayCISA orders urgent patching of actively exploited Zimbra flawCritical RCE flaw in Windows IKE Extension now actively exploitedCISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws

Actively Exploited
CISA
Firebox
Ransomware
RCE
Remote Code Execution
WatchGuard

Sergiu Gatlan
Sergiu is a news reporter who has covered the latest cybersecurity and technology developments for over a decade. Email or Twitter DMs for tips.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

N-able patches max severity N-central flaw amid ongoing attacks

Sponsor Posts

Overdue a password health-check? Audit your Active Directory for free

CTI Starter Kit + 2026 SANS CTI Survey

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware groups are actively exploiting a critical Remote Code Execution (RCE) flaw within WatchGuard Firebox firewalls, which was flagged as being exploited in December. This vulnerability is formally tracked as CVE-2025-14733 and arises from an error in boundary checking, allowing unauthenticated threat actors to execute malicious code remotely through low-complexity attacks. This flaw affects various versions of the Firebox operating system, specifically Fireware OS 11.x and later (including 11.12.4_Update1), Fireware OS 12.x or later (including 12.11.5), and versions 2025.1 through 2025.1.3.

When WatchGuard released security patches for CVE-2025-14733 in December, the vendor noted that unpatched Firebox firewalls were vulnerable only if they were configured to utilize IKEv2 VPN. However, WatchGuard also acknowledged that compromise might persist even if vulnerable configurations were deleted, provided a branch office VPN connection to a static gateway peer remained configured. Furthermore, WatchGuard reported that attackers were actively exploiting this flaw in the wild and subsequently shared indicators of compromise to assist customers in checking for potential breaches on their devices.

The scope of the exposure has been significant, as the Internet security watchdog group Shadowserver cataloged over 115,000 unpatched Firebox firewalls exposed online in December, with nearly 9,000 instances remaining unsecured nine months later. CISA officially included CVE-2025-14733 in its Known Exploited Vulnerabilities (KEV) catalog in December, mandating that U.S. federal agencies secure their systems within one week as required by Binding Operational Directive (BOD) 22-01. This action follows previous directives issued by the agency, such as the order to patch another actively exploited WatchGuard flaw, CVE-2022-23176, affecting Firebox and XTM firewalls two years prior. Moreover, WatchGuard had previously patched an RCE vulnerability in September 2025, CVE-2025-9242, which was similarly related to CVE-2025-14733, leading to CISA’s subsequent tagging of the flaw as actively exploited.

The context of this vulnerability highlights broader security challenges. The reported information also touches upon how credential management impacts defense effectiveness, noting that once attackers gain valid credentials, prevention defenses sharply diminish, as only thirty-seven percent of their actions are blocked. This is further contextualized by metrics such as The Blue Report 2026, which measures defensive techniques across vast simulation environments. The incident underscores the ongoing necessity for rigorous patching protocols, particularly for network infrastructure components, and emphasizes the critical role proactive vulnerability management plays in mitigating the threat posed by ransomware operations.