CISA warns ransomware gangs exploiting critical WatchGuard firewall flaw

Nearly 9,000 unpatched Firebox devices remain exposed nine months after patch

edit
By LineZotpaper
Published
Read Time2 min
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware groups are now exploiting a critical vulnerability in WatchGuard Firebox firewalls, which the agency added to its Known Exploited Vulnerabilities catalog in December.

The flaw, tracked as CVE-2025-14733, is an out-of-bounds write vulnerability that allows unauthenticated attackers to execute remote code in low-complexity attacks. It affects Firebox firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and versions 2025.1 through 2025.1.3.

WatchGuard released security patches in December, at which point it stated that unpatched devices are vulnerable only if configured to use IKEv2 VPN, but warned that devices may still be compromised even if vulnerable configurations have been deleted if a branch office VPN to a static gateway peer remains configured. The company also confirmed that the flaw was being exploited in the wild and shared indicators of compromise.

Internet security watchdog Shadowserver reported over 115,000 unpatched Firebox firewalls exposed online in December. As of September, nearly 9,000 instances remain unsecured.

In a Thursday update to its catalog of actively exploited vulnerabilities, CISA said the flaw is now known to be used by ransomware gangs, though it provided no further details about the attacks. CISA first added the vulnerability to its catalog in December, ordering U.S. federal agencies to secure their systems within a week.

§

Analysis

Why This Matters

  • Nearly 9,000 unpatched WatchGuard firewalls remain online after nine months, presenting a large attack surface for ransomware operators.
  • CISA's confirmation that ransomware gangs are exploiting the flaw indicates that threat actors are actively weaponizing the vulnerability for extortion.
  • Organizations that have not patched face a direct risk of network compromise, data encryption, and operational disruption.

Background

CVE-2025-14733 is an out-of-bounds write vulnerability in WatchGuard Firebox firewalls that was disclosed and patched in December 2025. WatchGuard issued security updates and indicators of compromise after confirming active exploitation. The flaw affects a broad range of Fireware OS versions, and exploitation requires only that IKEv2 VPN is configured. CISA added the flaw to its Known Exploited Vulnerabilities catalog in December, mandating federal agencies patch within a week. Despite the patch, thousands of devices remain exposed.

Key Perspectives

CISA: The agency is sounding an alarm that ransomware actors are now using this vulnerability, pushing for rapid patching by federal agencies and urging all organizations to take action. WatchGuard: The vendor has released patches and IoCs, but the vulnerability's continued exploitation highlights the challenge of getting organizations to apply updates promptly. Critics/Skeptics: The nine-month delay in patching by many organizations suggests that vulnerability disclosure and patch notification alone are insufficient; stronger enforcement or automated remediation may be needed.

What to Watch

  • The number of unpatched devices over the coming weeks, as Shadowserver continues to monitor.
  • Whether any specific ransomware group claims responsibility for attacks using this exploit.
  • Potential for CISA to issue a supplemental directive or emergency directive if attacks escalate.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.