The US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability that it flagged as being actively exploited in December. This vulnerability is tracked as CVE-2025-14733 and is due to an off-network entry that allows unauthenticated attackers to remotely execute malicious code in low sophistication attacks. This vulnerability affects firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x and later (including 12.11.5), and versions 2025.1 through 2025.1.3. In releasing security patches CVE-2025-14733 in December, WatchGuard said unpatched Firebox firewalls were only vulnerable to attack if they were configured to use IKEv2 VPN, but noted that they could still be compromised even if the vulnerable configurations were removed if the branch-to-static gateway VPN was still configured. WatchGuard also confirmed that the attackers were use of discovered vulnerabilities and common indicators of compromise to help customers verify if their Firebox devices have been compromised. Internet security watchdog group Shadowserver found more than 115,00 unpatched Firebox firewalls found on the Internet in December, with nearly 9,000 instances remaining unprotected nine months later. WatchGuard firewall vulnerability discovered on network (Shadowserver) In an update on Thursday to its catalog of actively exploited vulnerabilities, the US Cybersecurity and Infrastructure Security Agency (CISA) said vulnerability CVE-2025-14733 is now known to be used by ransomware gangs, but did not provide more details about their attacks. CISA first added the vulnerability to its catalog of known exploitable vulnerabilities (KEVs) in December, when it ordered US federal agencies to secure their systems within a week, as required by Binding Operational Directive (BOD) 22-01. Two years ago, the cybersecurity agency ordered government agencies to patch another actively exploited WatchGuard vulnerability (CVE-2022-23176) affecting the Firebox and XTM firewalls. Most recently, in September 2025, WatchGuard was updated. RCE vulnerability (CVE-2025-9242) affecting Firebox and almost identical to CVE-2025-14733. A month later CISA has flagged the vulnerability as being actively exploited and Shadowserver has identified over 75,000 Firebox firewalls that are vulnerable to attack. WatchGuard serves more than 250,000 small and midsize businesses through a network of more than 17,000 resellers and security service providers worldwide. General prevention scores may obscure what happens after initial access. Once attackers use valid credentials, prevention effectiveness drops dramatically. The Blue Report 2026 measures security technique by technique based on 338 million simulations run in customer production environments. Get report Post navigation Why Nirvana’s “Smells Like Teen Spirit” became a hit that no one expected – UNCUT England vs Pakistan: Third Men’s Cricket Test, Day Two – Live