AIO APEX

CISA confirms ransomware gangs are now exploiting a WatchGuard firewall flaw

BleepingComputer
Share:
CISA confirms ransomware gangs are now exploiting a WatchGuard firewall flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed Thursday that ransomware gangs are now exploiting a critical WatchGuard Firebox firewall vulnerability first flagged as actively exploited back in December — nine months during which nearly 9,000 unpatched devices have remained exposed online.

The flaw, tracked as CVE-2025-14733, stems from an out-of-bounds write that lets unauthenticated attackers execute malicious code remotely in low-complexity attacks. It affects Firebox firewalls running Fireware OS 11.x and later, 12.x and later, and versions 2025.1 through 2025.1.3. WatchGuard said devices are primarily vulnerable when configured for IKEv2 VPN, but warned that firewalls could remain exposed even after that configuration is removed, if a branch-office VPN to a static gateway peer is still active.

Nine months of exposure, and counting

WatchGuard patched CVE-2025-14733 in December and confirmed active exploitation at the time, sharing indicators of compromise so customers could check whether their devices had been hacked. Security watchdog Shadowserver counted more than 115,000 unpatched Firebox firewalls exposed online in December. As of this month, nearly 9,000 instances remain unsecured — a reminder that CISA's Known Exploited Vulnerabilities catalog entries don't guarantee remediation, even for federal agencies bound by binding operational directives.

CISA's Thursday update didn't disclose details of the ransomware campaigns now using the flaw, but the escalation from opportunistic exploitation to ransomware deployment typically signals that access brokers have begun selling compromised WatchGuard footholds to extortion groups — a common pattern once a vulnerability's exploitation code becomes reliable and widely available.

A firewall vendor's recurring problem

This is not WatchGuard's first actively-exploited firewall flaw. In September 2025, the company patched a nearly identical RCE bug, CVE-2025-9242, which CISA tagged as actively exploited within a month; Shadowserver found more than 75,000 vulnerable devices at the time. Two years before that, CISA warned of a separate WatchGuard flaw, CVE-2022-23176, being exploited by Russian state-linked hackers targeting Firebox and XTM firewalls.

WatchGuard provides security appliances to more than 250,000 small and mid-sized businesses through a network of over 17,000 resellers — a customer base that skews toward organizations with less dedicated security staff to track advisories and apply patches quickly. Administrators running Firebox firewalls should confirm they are on a patched Fireware OS build and check for the indicators of compromise WatchGuard published alongside the December advisory, regardless of whether IKEv2 VPN is still configured. As first reported by BleepingComputer.

Originally reported by BleepingComputer. Read the original article for additional details.

View original source
Share: