CISA flags WatchGuard Firebox RCE in ransomware use
CISA's Known Exploited Vulnerabilities catalog now marks CVE-2025-14733, a WatchGuard Firebox iked remote code execution bug first listed in December 2025, as used in ransomware campaigns. Shadowserver still counts nearly 9,000 exposed Fireboxes after nine months.

BleepingComputer, in a 10 September 2026 report by Sergiu Gatlan, says CISA updated its Known Exploited Vulnerabilities catalog so CVE-2025-14733 is now marked as used in ransomware campaigns. Gatlan is reporting that catalog field change, not a fresh WatchGuard disclosure.
This is an escalation of a December 2025 KEV row, not a new WatchGuard zero-day dated September 2026. The CVE was disclosed and first listed then. The WatchGuard patch note is still the one to work from.
The bug is an out-of-bounds write in the Fireware OS iked process that allows unauthenticated remote code execution at low complexity. CISA first added it on 19 December 2025 with a 26 December federal due date under BOD 22-01. The September update sets ransomware campaign use to Known, and CISA did not name the families or publish victim counts in the update Gatlan describes.
WatchGuard advisory WGSA-2025-00027 remains the patch source. Affected Fireware lines run through 11.12.4_Update1, 12.11.5, and 2025.1 through 2025.1.3. Fixed floors are 11.12.4_Update2 and later, 12.11.6 and later, and 2025.1.4 and later, plus the matching T15/T35 branch (12.5.15 and later on WatchGuard's table).
The attack path is IKEv2: Mobile User VPN with IKEv2, and Branch Office VPN with a dynamic gateway peer. WatchGuard warned that a device can stay at risk if a branch office VPN to a static gateway peer remains, even after the vulnerable configs were deleted.
Shadowserver, as cited by BleepingComputer, found over 115,000 unpatched Fireboxes on the internet in December. Nearly 9,000 were still exposed after nine months. WatchGuard, in the same report, serves more than 250,000 SMBs through more than 17,000 resellers.
Related KEV and edge-device notes on Cyberpresso include Cisco Secure FMC under active attack and CISA's ownCloud, Linux, and Artifactory batch. The same catalog pattern shows up in the three-day SharePoint, vCenter, macOS, and IKE window and in Microsoft's September Patch Tuesday.
If you still run Firebox, move Fireware to 12.11.6, 2025.1.4, 11.12.4_Update2, or the T15/T35 12.5.15 floor now. Then remove leftover IKEv2 and static-peer VPN configs so a patched image is not sitting next to an old tunnel that WatchGuard still treats as exposed.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free