Ransomware Crews Now Hitting Unpatched WatchGuard Firewalls, CISA Warns

A critical flaw in WatchGuard Firebox firewalls, patched in December, is now being used in ransomware attacks. Nearly 9,000 devices remain exposed online.

ThreatVectr Newsdesk· 3 min read
Close-up overhead view of dense rack-mounted network hardware in a dimly lit server room, indicator lights glowing amber and red across multiple units, cables b
Share

Key points

  • Ransomware gangs are now exploiting CVE-2025-14733, a critical flaw in WatchGuard Firebox firewalls, according to a CISA update on Thursday.
  • The bug lets attackers run their own code on the firewall over the internet, with no login required.
  • WatchGuard released patches in December 2024, but Shadowserver still counts roughly 9,000 unpatched devices exposed online, down from more than 115,000.
  • The flaw affects Fireware OS 11.x, 12.x and 2025.1 through 2025.1.3, in configurations that use the IKEv2 VPN feature.
  • WatchGuard serves more than 250,000 small and mid-sized businesses worldwide, meaning many potential downstream victims.

Ransomware gangs are now breaking into unpatched WatchGuard firewalls to plant file-locking malware on the networks behind them.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), the federal body that tracks active cyber threats, added that detail on Thursday to its running list of bugs known to be under attack. The flaw in question is CVE-2025-14733, a serious weakness in WatchGuard's Firebox line of firewalls (the boxes that sit at the edge of a company network and decide what traffic is allowed in and out).

CISA did not name the ransomware crews involved or say how many victims there are.

What exactly is the bug?

It is an out-of-bounds write flaw, meaning the firewall's software can be tricked into writing data where it should not, and an attacker anywhere on the internet can use that mistake to run their own commands on the device. No username or password is needed. WatchGuard's own advisory rates the attack as low complexity, in plain terms, easy to pull off once you know how.

The hole exists in firewalls set up to use IKEv2 VPN, a common way of building encrypted tunnels for remote staff and branch offices. WatchGuard has warned that even customers who removed the vulnerable VPN settings can still be at risk if a branch-office VPN pointing to a fixed partner address is still switched on.

Which devices need patching?

Any Firebox firewall running the affected versions of Fireware OS, WatchGuard's firewall operating system. The vendor pushed fixes in December 2024 and published indicators that defenders can use to check whether their box has already been broken into.

Affected Fireware OS Status
11.x, including 11.12.4_Update1 Vulnerable, patch available
12.x, including 12.11.5 Vulnerable, patch available
2025.1 through 2025.1.3 Vulnerable, patch available

Internet scanning group Shadowserver counted more than 115,000 exposed, unpatched Firebox devices online in December. Nine months later, roughly 9,000 are still sitting there unfixed.

Why does this matter beyond IT teams?

Because WatchGuard sells mainly to small and mid-sized businesses: dentists, law firms, local manufacturers, regional retailers. The company says its kit is deployed at more than 250,000 such organisations through 17,000 resellers. When a firewall like this is taken over, the attackers effectively hold the front door of the whole company network. From there, ransomware crews typically move sideways, steal data, and lock file servers, the kind of incident that closes a small business for days or weeks.

Ordinary customers of an affected business will not see anything directly, but if you get a letter saying your dentist or accountant suffered a cyberattack in the coming weeks, this bug is one plausible cause. Watch for unexpected password-reset emails and phishing that name-checks the business, both are common follow-ups.

Has this happened before with WatchGuard?

Yes, and recently. As reported by BleepingComputer, WatchGuard patched an almost identical remote code execution flaw, CVE-2025-9242, in September 2025. CISA flagged that one as actively exploited a month later, when Shadowserver still saw more than 75,000 vulnerable Fireboxes online. Back in 2022, another Firebox bug, CVE-2022-23176, was used by a Russian state-linked botnet before agencies were ordered to patch it.

The pattern is familiar. Fix ships, most people ignore it, criminals catch up.

© 2026 Threat Vectr