Skip to main content
Emerging ThreatsMalware & Ransomware

Ransomware gangs exploit WatchGuard firewall flaw

Network operations room with firewall device centered in foreground.

CVE-2025-14733: a low-complexity, unauthenticated remote code execution

CVE-2025-14733 is a critical vulnerability in WatchGuard Firebox firewalls that "stems from an out-of-bounds write allowing unauthenticated threat actors to execute malicious code remotely in low-complexity attacks," according to the filing cited by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The flaw affects appliances running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and 2025.1 through 2025.1.3.

When WatchGuard released patches for CVE-2025-14733 in December, the company said unpatched Firebox firewalls were vulnerable to attacks only if configured to use IKEv2 VPN. WatchGuard also warned, however, that devices "might still be compromised even if the vulnerable configurations have been deleted if a branch office VPN to a static gateway peer is still configured."

CISA: ransomware gangs now using CVE-2025-14733

In a Thursday update to its catalog of actively exploited vulnerabilities, CISA said the CVE-2025-14733 flaw "is now known to be used by ransomware gangs" but did not provide further details about the attacks. CISA first added the flaw to its Known Exploited Vulnerabilities (KEV) catalog in December and, at that time, ordered U.S. federal agencies to secure their systems within a week as required by Binding Operational Directive (BOD) 22-01.

Internet exposure: Shadowserver's counts in December and later

The internet security watchdog group Shadowserver reported that "over 115,00 unpatched Firebox firewalls exposed online in December," and that "nearly 9,000 instances remain unsecured after nine months." Separately, the source notes that following a September 2025 WatchGuard patch for a defect described as "almost identical to CVE-2025-14733," Shadowserver found "more than 75,000 Firebox firewalls vulnerable to attacks" one month later.

WatchGuard footprint and past advisories

WatchGuard sells through an extensive channel: the company "provides services to more than 250,000 small and mid-sized companies through a network of more than 17,000 security resellers and service providers worldwide." CISA's action on CVE-2025-14733 follows earlier directives: two years earlier the agency ordered government agencies to patch another actively exploited WatchGuard flaw, CVE-2022-23176, which affected Firebox and XTM firewalls.

What this means for technologists, policymakers, and affected enterprises

  • Technologists and security teams: The vulnerability is exploitable without authentication and has been tied to ransomware operations, and WatchGuard's advisory specifically calls out IKEv2 VPN configurations and the persistent risk posed by branch office VPNs to static gateway peers.
  • Policymakers and federal agencies: CISA has placed CVE-2025-14733 in its KEV catalog and previously used BOD 22-01 to require a one-week mitigation window for federal systems; the agency's recent update now ties the vulnerability to ransomware gangs even as it declined to disclose operational details.
  • Affected enterprises and procurement leaders: WatchGuard's large installed base—"more than 250,000" customers and "more than 17,000" resellers—means the reach of this vulnerability is broad, and Shadowserver's internet scans show substantial numbers of exposed or unpatched devices months after initial advisories.

The record compiled here is starkly practical: a remotely exploitable, low-complexity bug affecting widely deployed firewall software has been flagged by CISA as an active tool of ransomware operators, yet significant numbers of devices remained discoverable on the internet months after patches and advisories were issued. The Blue Report 2026 offers a complementary caution: "Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply." If defenders are to close this gap, the facts in the record point to two concrete frictions to watch—the specific VPN configurations WatchGuard named, and the continued internet exposure counts Shadowserver published.

Original story