Ransomware Gangs Join Attacks on Unpatched WatchGuard Fireboxes

The U.S. Cybersecurity and Infrastructure Security Agency has added a critical WatchGuard Firebox vulnerability to its known exploited catalog, confirming that ransomware groups are now using it. The flaw, tracked as CVE-2025-14733, allows remote code execution via an out-of-bounds write and affects many Fireware OS versions. Despite patches released in December, nearly 9,000 vulnerable devices remain exposed online.
The vulnerability stems from an out-of-bounds write permitting unauthenticated remote code execution. WatchGuard initially cautioned that exposure depended on IKEv2 VPN settings, yet warned that residual branch office VPN configurations could still leave devices susceptible even after removing vulnerable settings.
Shadowserver identified over 115,000 exposed units in December, with nearly 9,000 still unpatched months later. This mirrors past incidents, including CISA's earlier mandate for CVE-2022-23176 and a similar 2025 flaw, CVE-2025-9242, which exposed over 75,000 devices.
The confirmed ransomware exploitation of these firewalls could significantly impact small and mid-sized businesses, which form the bulk of WatchGuard's client base. Since these devices act as network gateways, successful attacks may lead to widespread operational disruption, data theft, and costly extortion demands. The lingering number of unpatched units suggests that many organizations may struggle with timely patch management, potentially leaving critical infrastructure exposed to criminal groups.