CISA: WatchGuard RCE flaw now exploited in ransomware attacks
Recorded: Sept. 10, 2026, 10:01 a.m.
| Original | Summarized |
CISA: WatchGuard RCE flaw now exploited in ransomware attacks News Featured AdaptHealth confirms 4.1 million people exposed in July cyberattack Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Over 36,000 exposed Plex servers vulnerable to recent flaws New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access CISA: WatchGuard RCE flaw now exploited in ransomware attacks Microsoft fixes bug that wiped Windows desktop settings Trezor warns users of email provider breach, phishing attacks Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurityCISA: WatchGuard RCE flaw now exploited in ransomware attacks CISA: WatchGuard RCE flaw now exploited in ransomware attacks By Sergiu Gatlan September 10, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. Vulnerable WatchGuard firewalls exposed online (Shadowserver) Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Related Articles: Actively Exploited Sergiu Gatlan Previous Article Post a Comment Community Rules You need to login in order to post a comment Not a member yet? Register Now You may also like: Upcoming Webinar Popular Stories Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations N-able patches max severity N-central flaw amid ongoing attacks Sponsor Posts Overdue a password health-check? Audit your Active Directory for free CTI Starter Kit + 2026 SANS CTI Survey Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance. Upcoming Webinar Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware groups are actively exploiting a critical Remote Code Execution (RCE) flaw within WatchGuard Firebox firewalls, which was flagged as being exploited in December. This vulnerability is formally tracked as CVE-2025-14733 and arises from an error in boundary checking, allowing unauthenticated threat actors to execute malicious code remotely through low-complexity attacks. This flaw affects various versions of the Firebox operating system, specifically Fireware OS 11.x and later (including 11.12.4_Update1), Fireware OS 12.x or later (including 12.11.5), and versions 2025.1 through 2025.1.3. When WatchGuard released security patches for CVE-2025-14733 in December, the vendor noted that unpatched Firebox firewalls were vulnerable only if they were configured to utilize IKEv2 VPN. However, WatchGuard also acknowledged that compromise might persist even if vulnerable configurations were deleted, provided a branch office VPN connection to a static gateway peer remained configured. Furthermore, WatchGuard reported that attackers were actively exploiting this flaw in the wild and subsequently shared indicators of compromise to assist customers in checking for potential breaches on their devices. The scope of the exposure has been significant, as the Internet security watchdog group Shadowserver cataloged over 115,000 unpatched Firebox firewalls exposed online in December, with nearly 9,000 instances remaining unsecured nine months later. CISA officially included CVE-2025-14733 in its Known Exploited Vulnerabilities (KEV) catalog in December, mandating that U.S. federal agencies secure their systems within one week as required by Binding Operational Directive (BOD) 22-01. This action follows previous directives issued by the agency, such as the order to patch another actively exploited WatchGuard flaw, CVE-2022-23176, affecting Firebox and XTM firewalls two years prior. Moreover, WatchGuard had previously patched an RCE vulnerability in September 2025, CVE-2025-9242, which was similarly related to CVE-2025-14733, leading to CISA’s subsequent tagging of the flaw as actively exploited. The context of this vulnerability highlights broader security challenges. The reported information also touches upon how credential management impacts defense effectiveness, noting that once attackers gain valid credentials, prevention defenses sharply diminish, as only thirty-seven percent of their actions are blocked. This is further contextualized by metrics such as The Blue Report 2026, which measures defensive techniques across vast simulation environments. The incident underscores the ongoing necessity for rigorous patching protocols, particularly for network infrastructure components, and emphasizes the critical role proactive vulnerability management plays in mitigating the threat posed by ransomware operations. |