CISA Confirms Ransomware Gangs Exploit Critical WatchGuard Firebox Flaw

Antonio Garcia  - Web Content Manager
Last updated: September 10, 2026
Human Written
Share
Ransomware Gangs Exploit Critical WatchGuard Firewall Flaw, CISA Warns
Radar Rundown
  • CISA now confirms that ransomware gangs are exploiting a serious bug in WatchGuard Firebox firewalls.

  • The flaw lets hackers run harmful code from anywhere, without needing a username or password.

  • Nearly 9,000 firewalls remain exposed, nine months after WatchGuard released a fix for the bug.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) shared new information this week. Ransomware gangs are now using a critical WatchGuard Firebox firewall flaw to break into networks. CISA first warned that hackers were exploiting this bug back in December.

A flaw that lets hackers in without a password

This bug carries the tracking number CVE-2025-14733. It comes from an out-of-bounds write error inside the firewall’s code. This type of error happens when a program writes data outside its proper memory space.

Hackers do not need a password to use this flaw. They also do not need much skill to pull it off. Security experts call this a low-complexity attack, which means many attackers can copy it easily.

The bug affects several versions of WatchGuard’s Fireware OS. This includes version 11.x and later, such as 11.12.4_Update1. It also includes version 12.x and later, such as 12.11.5. Versions 2025.1 through 2025.1.3 are affected too.

WatchGuard released a security patch for this flaw back in December. According to WatchGuard, unpatched firewalls only face risk if they use IKEv2 VPN settings. However, the company warned that danger can remain even after someone deletes those settings. A firewall stays at risk if it still has a branch office VPN linked to a fixed gateway peer.

WatchGuard also confirmed that hackers were already using this flaw in real attacks. The company shared a list of warning signs so customers could check their own devices. These signs help IT teams spot whether their firewall has already been hacked.

Thousands of firewalls still sit wide open

A security research group called Shadowserver tracks flaws like this one across the internet. In December, Shadowserver found more than 115,000 unpatched WatchGuard firewalls sitting online. Each one stood open to attack.

Nine months later, the number has dropped a lot, but the risk has not disappeared. Nearly 9,000 firewalls remain unsecured today. That means thousands of businesses could still face a ransomware attack through this same hole.

CISA posted an update to its Known Exploited Vulnerabilities catalog on Thursday. The agency confirmed that ransomware groups now use this flaw as an entry point. CISA did not share further details about who these gangs are or how they strike.

A pattern of firewall attacks that keeps repeating

CISA added this flaw to its Known Exploited Vulnerabilities catalog back in December. At that time, the agency gave federal agencies just one week to fix their systems. This rule comes from a federal order called Binding Operational Directive 22-01.

California has introduced $200 daily fines for data brokers that fail to process consumer deletion requests within 45 days. The law also protects 350,000 residents already registered on its opt-out platform and requires companies to explain rejections and maintain audit logs.

This is not the first time WatchGuard firewalls have faced this kind of danger. Two years ago, CISA ordered agencies to patch a different bug, tracked as CVE-2022-23176. That earlier flaw hit both Firebox and XTM firewall models.

A similar pattern showed up again more recently. In September 2025, WatchGuard patched another remote code execution bug, tracked as CVE-2025-9242. This flaw looked almost identical to the one making news today. One month later, CISA flagged that bug as actively exploited too. Shadowserver found more than 75,000 vulnerable Firebox firewalls at that time.

WatchGuard plays a big role in business security around the world. The company serves more than 250,000 small and mid-sized businesses. It works through a network of over 17,000 security resellers and service providers globally.

Businesses using WatchGuard firewalls should check their systems against the known warning signs right away. IT teams should also confirm they have installed the December patch for CVE-2025-14733. Waiting could leave a business exposed to the same attack path that ransomware gangs are already using.

This flaw shows a pattern that keeps repeating across the security world. A bug appears, hackers exploit it, and thousands of devices stay unpatched for months. Businesses that treat every warning as urgent stand a far better chance of staying safe.

Share this article

About the Author

Antonio Garcia

Antonio Garcia

Web Content Manager

Antonio is a Web Content Manager at PrivacyRadar. He has worked with multiple renowned publishers worldwide in relevant positions. Antonio has excellent social and commnunication skills, innovation, detail-oriented, and a keen manager. He always tries to get to the root of the problem and solves it. This is what alligns him with PrivacyRadar's vision. He also boasts great knowledge about online security and privacy.

More from Antonio Garcia

Comments

No comments.