CISA: WatchGuard RCE flaw now exploited in ransomware attacks
CISA has updated its Known Exploited Vulnerabilities catalog to confirm that ransomware operators are now leveraging CVE-2025-14733, a critical out-of-bounds write flaw in WatchGuard Firebox firewalls. This vulnerability allows unauthenticated attackers to achieve remote code execution on devices running Fireware OS 11.x (including 11.12.4_Update1), 12.x (including 12.11.5), or versions between 2025.1 and 2025.1.3, specifically when configured for IKEv2 VPN. While WatchGuard released remediation patches in December and warned that residual risk exists even if the vulnerable configuration is removed, nearly 9,000 exposed instances remain unpatched. Administrators should immediately apply updates and review IKEv2 settings to mitigate this active threat.