CISA has updated its Known Exploited Vulnerabilities entry for CVE-2025-14733 to record that ransomware gangs are now exploiting the critical WatchGuard Firebox out-of-bounds write, which the agency first flagged as exploited in December 2025. The flaw allows unauthenticated attackers to execute code remotely in low-complexity attacks against Fireware OS 11.x and later, 12.x and later, and 2025.1 through 2025.1.3. CISA has not detailed the ransomware activity observed.
| Attribute | Detail |
|---|---|
| Vulnerability | CVE-2025-14733 โ out-of-bounds write, unauthenticated RCE |
| Vendor | WatchGuard (Firebox / Fireware OS) |
| Disclosed | December 2025 (WatchGuard advisory WGSA-2025-00027, IoCs published) |
| KEV | Added December 2025; updated 2026-09-10 for ransomware use |
| Exposure | 115,000+ Fireboxes exposed at disclosure; ~9,000 still unpatched September 2026 |
| Detection | Unpatched devices may stay compromised after vulnerable configs are deleted |
WatchGuard's advisory warns that Firebox devices are exploitable where IKEv2 VPN is configured, but that they may still be compromised even if the vulnerable configurations have been deleted, provided a branch-office VPN to a static gateway peer remains configured โ making indicator checks, not just patching, the necessary remedial step. The nine-month span between disclosure and confirmed ransomware use, against a Shadowserver count that still finds nearly 9,000 unpatched instances online, makes this a standing example of the shrinking exploitation window measured against an unchanged remediation window. Australian and New Zealand SMB and MSP estates running Firebox firewalls should treat the KEV update as a prompt to verify patch state and hunt for the vendor's published indicators of attack. See cve-2025-14733.md.