CISA: WatchGuard RCE flaw now exploited in ransomware attacks
CISA confirms ransomware gangs are exploiting critical unauthenticated RCE CVE-2025-14733 in WatchGuard Firebox firewalls, with roughly 9,000 devices still unpatched.
CVE-2025-14733 is an out-of-bounds write in WatchGuard Fireware OS allowing unauthenticated remote code execution, exploitable on firewalls configured for IKEv2 VPN and potentially even after the configuration was deleted if a static branch-office VPN peer remains. WatchGuard released patches in December and confirmed in-the-wild exploitation; Shadowserver found over 115,000 exposed Fireboxes at the time, with nearly 9,000 still unpatched after nine months. CISA added the flaw to its Known Exploited Vulnerabilities catalog in December under BOD 22-01 and on Thursday confirmed ransomware gangs are now exploiting it, without providing campaign details. WatchGuard serves more than 250,000 small and mid-sized companies through 17,000+ security resellers and service providers.
- CVE-2025-14733 is an out-of-bounds write enabling unauthenticated remote code execution on IKEv2 VPN-configured Fireboxes.
- CISA added the flaw to its KEV catalog in December, ordering federal patching within a week.
- Shadowserver found over 115,000 exposed Fireboxes in December; nearly 9,000 remain unpatched after nine months.
- WatchGuard serves over 250,000 SMBs through 17,000+ resellers and published IOCs to check compromise.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-23176 | Privilege Escalation in WatchGuard Firebox/XTM Fireware OS WatchGuard Firebox and XTM appliances running affected versions of Fireware OS contain a privilege escalation flaw that allows a remote attacker who already holds unprivileged credentials to obtain a privileged management session via exposed management access. The flaw is triggered when management access is exposed (for example, to the internet) and an attacker authenticates with low-privileged credentials, at which point they can elevate to privileged management of the appliance. Because the CVSS v3.1 score of 8.8 carries high confidentiality, integrity, and availability impact, full compromise of the appliance is the realistic outcome. Organizations running Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U3, or 12.2.x through 12.5.x before 12.5.7_U3 are affected. The vulnerability is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-04-11, and the Russia-linked Cyclops Blink botnet used it as an initial access vector to infect thousands of devices before the FBI disrupted the botnet. Do: Upgrade affected Fireware OS branches to 12.7.2_U1, 12.1.3_U3, or 12.5.7_U3 (or later) per WatchGuard's instructions, as required by CISA's KEV catalog. Until patched, restrict appliance management access to trusted networks or management VPNs rather than exposing it to the internet. Because this flaw was used to deploy the Cyclops Blink botnet, administrators should also check Firebox/XTM devices for signs of that compromise using vendor detection guidance. | 8.8 | 13% | KEV |
| masson the order of 100,000+ potentially exposed Firebox/XTM appliances (WatchGuard's installed base is cited in the millions, with management access commonly… | |
| CVE-2025-14733 | Unauthenticated Out-of-Bounds Write RCE in WatchGuard Fireware OS CVE-2025-14733 is an out-of-bounds write (CWE-787) in the iked process of WatchGuard Fireware OS on Firebox appliances, allowing a remote, unauthenticated attacker to execute arbitrary code. The flaw is reachable when the appliance is configured for Mobile User VPN with IKEv2 or a branch office VPN (BOVPN) using IKEv2 with a dynamic gateway peer; a Firebox may also remain vulnerable if those IKEv2 configurations were previously set up and then deleted while a BOVPN to a static gateway peer is still configured. Successful exploitation gives an attacker arbitrary code execution on the firewall itself, a high-value network position that can be used for further lateral movement. Affected deployments are WatchGuard Firebox appliances running Fireware OS with the described IKEv2 VPN configurations, since the IKEv2 service by definition listens on the external interface. The vulnerability is under active exploitation: it was added to CISA's KEV catalog on 2025-12-19 with known ransomware use, carries an EPSS probability of 26.5% (98th percentile) of exploitation within 30 days, and no public proof-of-concept is currently known. Do: Upgrade affected Firebox appliances to the patched Fireware OS builds identified in WatchGuard's security advisory, per CISA KEV required action and applicable BOD 22-01 guidance. Audit configurations for Mobile User VPN with IKEv2 and BOVPN IKEv2 with a dynamic gateway peer, including appliances where those settings were deleted but a BOVPN to a static gateway peer is still configured, as these may remain vulnerable. Until patched, restrict IKEv2 traffic (UDP 500/4500) to trusted source addresses or discontinue use if mitigations are unavailable. | 9.3 | 27% | KEV ransomware |
| largeplausibly in the tens of thousands of internet-exposed Firebox appliances (order of magnitude 10^4 to 10^5); unknown precisely | |
| CVE-2025-9242 | Out-of-Bounds Write in WatchGuard Fireware OS iked Enables Unauthenticated RCE WatchGuard Fireware OS contains an out-of-bounds write (CWE-787) in the iked process that a remote, unauthenticated attacker can trigger to execute arbitrary code on the appliance. The flaw is reachable via the mobile user VPN with IKEv2 and via branch office VPNs using IKEv2 to a dynamic gateway peer; devices whose IKEv2 configurations were deleted may remain vulnerable if a branch office VPN to a static gateway peer is still configured. Successful exploitation yields full system compromise, reflected in the CVSS v4.0 base score of 9.3 (network vector, no privileges or user interaction, high impact on confidentiality, integrity and availability). WatchGuard Firebox appliances with IKEv2 VPN services are affected, with public reporting citing roughly 54,000 internet-exposed Fireboxes; the issue was added to CISA's Known Exploited Vulnerabilities catalog on 2025-11-12, a public proof-of-concept exploit exists, and headlines indicate use in ransomware attacks (KEV ransomware field is listed as unknown). EPSS assigns a 91.3% probability of exploitation within 30 days (100th percentile), so remediation urgency is high. Do: Apply the patched Fireware OS release per WatchGuard's security advisory immediately (exact fixed version numbers are not provided in the source data); the KEV listing makes BOD 22-01 remediation timelines mandatory for U.S. federal agencies. As an interim mitigation, restrict or disable IKEv2 VPN exposure — mobile user VPN with IKEv2 and branch office VPN IKEv2, including residual static-peer BOVPN configurations on devices that previously had IKEv2 configured — to trusted sources only. Administrators should audit configuration history to identify Fireboxes with prior IKEv2 mobile VPN or dynamic-peer BOVPN setups, since these may remain vulnerable even after the configs were deleted. | 9.3 | 91% | KEV PoC |
| large≈54,000 internet-exposed Fireboxes (public scan figure cited in coverage) |
Full article400 words · extracted from bleepingcomputer.com · click to collapse

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December.
This flaw is tracked as CVE-2025-14733 and stems from an out-of-bounds write allowing unauthenticated threat actors to execute malicious code remotely in low-complexity attacks.
This vulnerability affects firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and 2025.1 through 2025.1.3.
When it released CVE-2025-14733 security patches in December, WatchGuard said unpatched Firebox firewalls are vulnerable to attacks only if configured to use IKEv2 VPN, but noted they might still be compromised even if the vulnerable configurations have been deleted if a branch office VPN to a static gateway peer is still configured.
WatchGuard also confirmed that attackers were exploiting the flaw in the wild and shared indicators of compromise to help customers check whether their Firebox devices have been hacked.
Internet security watchdog group Shadowserver found over 115,00 unpatched Firebox firewalls exposed online in December, and nearly 9,000 instances remain unsecured after nine months.

In a Thursday update to its catalog of actively exploited vulnerabilities, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said the CVE-2025-14733 flaw is now known to be used by ransomware gangs but has not provided more details about their attacks.
CISA first added the flaw to its Known Exploited Vulnerabilities (KEV) catalog in December, when it ordered U.S. federal agencies to secure their systems within a week, as mandated by Binding Operational Directive (BOD) 22-01.
Two years ago, the cybersecurity agency ordered government agencies to patch another actively exploited WatchGuard flaw (CVE-2022-23176) affecting Firebox and XTM firewalls.
More recently, in September 2025, WatchGuard patched an RCE vulnerability (CVE-2025-9242) affecting Firebox firewalls and almost identical to CVE-2025-14733. One month later, CISA tagged the flaw as actively exploited, and Shadowserver found more than 75,000 Firebox firewalls vulnerable to attacks.
WatchGuard provides services to more than 250,000 small and mid-sized companies through a network of more than 17,000 security resellers and service providers worldwide.
Once attackers have valid credentials, only 37% of their actions are blocked
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.bleepingcomputer.com/news/security/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks/