CVE Tools
Back to feed
Exploited in the wild WatchGuard Firebox ransomware WatchGuard rce

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

CISA has updated its Known Exploited Vulnerabilities catalog to confirm that ransomware operators are now leveraging CVE-2025-14733, a critical out-of-bounds write flaw in WatchGuard Firebox firewalls. This vulnerability allows unauthenticated attackers to achieve remote code execution on devices running Fireware OS 11.x (including 11.12.4_Update1), 12.x (including 12.11.5), or versions between 2025.1 and 2025.1.3, specifically when configured for IKEv2 VPN. While WatchGuard released remediation patches in December and warned that residual risk exists even if the vulnerable configuration is removed, nearly 9,000 exposed instances remain unpatched. Administrators should immediately apply updates and review IKEv2 settings to mitigate this active threat.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store