Ransomware gangs are now confirmed to be exploiting a critical vulnerability in WatchGuard Firebox firewalls, with WatchGuard Firebox ransomware attacks formally acknowledged in the latest update to the US Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalogue. The flaw in question, tracked as CVE-2025-14733, has been circulating in the wild since at least December, but Thursday’s catalogue update makes the ransomware connection official.
CVE-2025-14733 stems from an out-of-bounds write in WatchGuard’s Fireware operating system. Unauthenticated attackers can use it to execute malicious code remotely, and the attack complexity is rated low, the kind of combination that tends to attract opportunistic criminal operators fairly quickly. According to Decryption Digest, the flaw carries a CVSS score of 9.8, placing it at the very top of the severity scale.
The affected versions span a wide range: Fireware OS 11.x and later (including 11.12.4_Update1), 12.x and later (including 12.11.5), and 2025.1 through 2025.1.3. In short, if your Firebox hasn’t been patched and is configured for IKEv2 VPN, it’s in scope. WatchGuard added a wrinkle worth noting: even organisations that have already deleted the vulnerable IKEv2 configuration may still be exposed if a branch office VPN to a static gateway peer remains configured.
A Slow Patch Rate Keeping WatchGuard Firebox Ransomware Attacks in Play
The patch has been available since December, yet the numbers tracking remediation are not encouraging. Internet security watchdog group Shadowserver found over 115,000 unpatched Firebox firewalls exposed online when the flaw was first disclosed. Nine months on, nearly 9,000 instances remain unsecured and reachable from the internet, a figure that, while smaller, still represents a meaningful attack surface for ransomware operators who are now confirmed to be interested.
WatchGuard did its part at the time of disclosure: it released patches, confirmed active exploitation, and shared indicators of compromise so customers could check whether their Firebox devices had already been compromised. The slow remediation rate since then is, unfortunately, a familiar story for network edge devices.
CISA originally added CVE-2025-14733 to its KEV catalogue on 19 December 2025, according to Senserva, at the same time ordering US federal agencies to secure their systems within a week under Binding Operational Directive (BOD) 22-01. Thursday’s update does not substantially change the federal deadline calculus (that clock ran out months ago) but it does formally flag the ransomware dimension, which may prompt some private-sector operators to finally act.
Context: WatchGuard and CISA Have Been Here Before
This is not the first time CISA has had to push WatchGuard device patches. Two years ago, the agency ordered government bodies to address another actively exploited WatchGuard flaw, CVE-2022-23176, which affected Firebox and XTM firewalls. The pattern of WatchGuard edge devices turning up in CISA’s catalogue is becoming a recurring theme.
More recently, in September 2025, WatchGuard patched a separate remote code execution vulnerability, CVE-2025-9242, affecting Firebox firewalls and described as almost identical to CVE-2025-14733. One month after that patch landed, CISA tagged CVE-2025-9242 as actively exploited too. Shadowserver’s scan at that point found more than 75,000 Firebox firewalls still vulnerable. The parallels between the two CVEs, similar technical character, similar exploitation timelines, similar remediation drag, are hard to ignore.
The scale of potential exposure matters here. WatchGuard’s customer base runs to more than 250,000 small and mid-sized businesses, served through a network of more than 17,000 resellers and service providers worldwide. That is a substantial installed base, and small and mid-sized organisations are typically less well-resourced when it comes to rapid patch deployment on network edge equipment.
CISA has not provided further details on which ransomware groups are behind the current WatchGuard Firebox ransomware attacks, nor on the specific targets or scale of the campaign. WatchGuard’s indicators of compromise, published alongside the original December patch, remain the most actionable resource for administrators who want to determine whether their devices have already been accessed.

