WatchGuard Firebox Ransomware Exploitation

WatchGuard Firebox ransomware exploitation is now officially confirmed. CISA updated its Known Exploited Vulnerabilities catalog entry for CVE-2025-14733 on September 10, 2026, to reflect that ransomware gangs, not just opportunistic access brokers, are actively weaponizing a firewall flaw that has had a public patch available since December 2025.
What Happened
CVE-2025-14733 is an out-of-bounds write vulnerability in the iked process on WatchGuard Firebox firewalls, carrying a CVSS score of 9.3. It allows an unauthenticated remote attacker to execute arbitrary code in low-complexity attacks requiring no user interaction. WatchGuard states exposure requires IKEv2 VPN to be configured on the device; appliances can remain vulnerable even after that configuration is removed, if a branch-office VPN to a static gateway peer is still present.
CISA originally added this flaw to its KEV catalog in December 2025, flagging active exploitation at that time. The update this run is the confirmation that ransomware operators specifically have now joined the exploitation of this flaw as of the September 10, 2026 KEV update. WatchGuard has separately confirmed that attackers are exfiltrating device configuration files and management databases during these attacks, meaning credential exposure predates and survives the patch itself. The Shadowserver Foundation counted roughly 125,000 exposed WatchGuard Firebox IP addresses when this campaign was first tracked, and roughly 9,000 instances remain unpatched nine months after the fix shipped, per subsequent scanning.
Why It Matters
This is not a fresh zero-day: it is a nine-month-old flaw that ransomware crews only recently found worth the effort. That lag matters for how organizations prioritize patching: a vulnerability with a patch already available can still become a live ransomware vector months later, once exploitation tooling matures or a particular actor group decides the target population is worth it. For DACH Mittelstand organizations running WatchGuard Firebox as an edge firewall or VPN concentrator, an inventory that still lists this device as “patched, low priority” based on a December assessment is exactly the blind spot this development exploits. The confirmed credential exfiltration also means a late patch alone does not close the exposure; any credential the appliance held before patching should be considered compromised.
What You Should Do Now
- Patch immediately to Fireware 12.11.6, 2025.1.4, or 12.5.15, whichever matches your deployed branch; this is not optional regardless of whether IKEv2 VPN currently appears active.
- Verify exposure by checking whether your Firebox devices are internet-facing and whether IKEv2 VPN was ever configured, even if later removed; a prior branch-office VPN to a static peer can leave residual exposure.
- If no patch is possible immediately, restrict management and VPN interfaces to known administrative source ranges as an interim step, and monitor for anomalous configuration-export or database-access activity.
- Rotate every credential stored on or managed through the appliance (admin passwords, VPN pre-shared keys, RADIUS/LDAP service accounts), regardless of patch status, given WatchGuard’s own confirmation of config and database exfiltration.
DIESEC Perspective
This is the ninth-plus entry in the edge-device exploitation pattern DIESEC has tracked through 2026: FortiGate, Cisco SD-WAN, Palo Alto GlobalProtect, Check Point VPN, OPNsense, Ubiquiti UniFi, and now WatchGuard Firebox. The recurring lesson across all of them: initial exploitation by a narrower, access-focused actor is often followed months later by ransomware crews piling onto the same unpatched population once the access method is proven reliable. “No ransomware yet” was never a reason to deprioritize this patch, and this case makes that explicit.
Not sure whether your edge firewall inventory still reflects last year’s patch status? Contact DIESEC for a rapid patch verification and credential exposure review.
Sources: BleepingComputer | Security Affairs
Published: 2026-09-23 | Category: Vulnerabilities & Patches | ~4 min read

