MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-10 · via BleepingComputer

Ransomware Gangs Join Attacks on Unpatched WatchGuard Fireboxes

Image via BleepingComputer
Image via BleepingComputer

The U.S. Cybersecurity and Infrastructure Security Agency has added a critical WatchGuard Firebox vulnerability to its known exploited catalog, confirming that ransomware groups are now using it. The flaw, tracked as CVE-2025-14733, allows remote code execution via an out-of-bounds write and affects many Fireware OS versions. Despite patches released in December, nearly 9,000 vulnerable devices remain exposed online.

Expanded Detail

The vulnerability stems from an out-of-bounds write permitting unauthenticated remote code execution. WatchGuard initially cautioned that exposure depended on IKEv2 VPN settings, yet warned that residual branch office VPN configurations could still leave devices susceptible even after removing vulnerable settings.

Shadowserver identified over 115,000 exposed units in December, with nearly 9,000 still unpatched months later. This mirrors past incidents, including CISA's earlier mandate for CVE-2022-23176 and a similar 2025 flaw, CVE-2025-9242, which exposed over 75,000 devices.

Context

The confirmed ransomware exploitation of these firewalls could significantly impact small and mid-sized businesses, which form the bulk of WatchGuard's client base. Since these devices act as network gateways, successful attacks may lead to widespread operational disruption, data theft, and costly extortion demands. The lingering number of unpatched units suggests that many organizations may struggle with timely patch management, potentially leaving critical infrastructure exposed to criminal groups.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Emergency hotfix issued for critical N-central remote code execution bug · Cybersecurity
Cisco warns of active exploitation of critical firewall management flaw · Cybersecurity
SAP Patches Critical Kernel Flaw Allowing Remote Code Execution · Cybersecurity
Tens of thousands of internet-facing Plex servers still lack fixes for known security bugs · Cybersecurity
This summary is AI-generated and original to Mobble; the linked article is the authoritative source. Original headline: “CISA: WatchGuard RCE flaw now exploited in ransomware attacks.” Browse more stories.