CISA has confirmed ransomware groups are exploiting CVE-2025-14733, a critical unauthenticated remote-code-execution flaw in WatchGuard Firebox firewalls. The out-of-bounds write vulnerability affects multiple Fireware OS 11.x, 12.x, and 2025.1 releases, particularly devices using vulnerable IKEv2 VPN configurations; WatchGuard has issued patches, confirmed active exploitation, and published indicators of compromise.
Organizations should urgently patch affected Firebox appliances and investigate for compromise, as WatchGuard warned that some branch-office VPN configurations may remain exposed even after vulnerable settings are removed. CISA added the flaw to its Known Exploited Vulnerabilities catalog and directed U.S. federal agencies to remediate it within one week; despite more than 115,000 initially exposed unpatched devices, roughly 9,000 reportedly remained unsecured nine months later.

See which actors are running it and whether you're in range.
10 events from the most recent confirmed update back to the earliest known activity.
Nine months after Shadowserver's December finding, nearly 9,000 vulnerable internet-exposed Firebox firewall instances reportedly remained unsecured.
Shadowserver identified more than 115,000 internet-exposed WatchGuard Firebox firewalls that remained unpatched for CVE-2025-14733.
CISA added CVE-2025-14733 to its Known Exploited Vulnerabilities catalog and, under Binding Operational Directive 22-01, required U.S. federal agencies to remediate affected systems within one week.
WatchGuard released security patches for CVE-2025-14733, a critical out-of-bounds-write flaw enabling unauthenticated remote code execution on affected Firebox Fireware OS releases.
One month after WatchGuard patched CVE-2025-9242, CISA classified the Firebox vulnerability as actively exploited. Shadowserver had identified more than 75,000 Firebox firewalls vulnerable to exploitation.
WatchGuard issued a patch for CVE-2025-9242, a remote-code-execution vulnerability in Firebox devices.
WatchGuard confirmed that attackers exploiting CVE-2025-14733 were exfiltrating Firebox appliance configurations and management databases. It advised affected organizations to rotate appliance credentials even after applying the security update.
CISA confirmed that ransomware groups are exploiting the critical WatchGuard Firebox vulnerability CVE-2025-14733, but did not disclose technical or operational details of the attacks.
WatchGuard confirmed real-world exploitation of CVE-2025-14733 and published indicators of compromise to help Firebox customers identify potential compromise. It warned that affected IKEv2 VPN configurations are exposed and that certain branch-office VPN configurations may remain compromisable after vulnerable settings are removed.
CISA previously directed government agencies to patch the actively exploited CVE-2022-23176 vulnerability affecting WatchGuard Firebox and XTM firewalls.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcemkd-cirt.mk
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.