Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-11 ยท updated: 2026-09-11 ยท tags: [incident, watchguard, firebox, ransomware, kev, edge-device, active-exploitation] ยท confidence: high ยท severity: critical ยท affected_sectors: [government, technology, smb] ยท au_impact: true

CISA has updated its Known Exploited Vulnerabilities entry for CVE-2025-14733 to record that ransomware gangs are now exploiting the critical WatchGuard Firebox out-of-bounds write, which the agency first flagged as exploited in December 2025. The flaw allows unauthenticated attackers to execute code remotely in low-complexity attacks against Fireware OS 11.x and later, 12.x and later, and 2025.1 through 2025.1.3. CISA has not detailed the ransomware activity observed.

Attribute Detail
Vulnerability CVE-2025-14733 โ€” out-of-bounds write, unauthenticated RCE
Vendor WatchGuard (Firebox / Fireware OS)
Disclosed December 2025 (WatchGuard advisory WGSA-2025-00027, IoCs published)
KEV Added December 2025; updated 2026-09-10 for ransomware use
Exposure 115,000+ Fireboxes exposed at disclosure; ~9,000 still unpatched September 2026
Detection Unpatched devices may stay compromised after vulnerable configs are deleted

WatchGuard's advisory warns that Firebox devices are exploitable where IKEv2 VPN is configured, but that they may still be compromised even if the vulnerable configurations have been deleted, provided a branch-office VPN to a static gateway peer remains configured โ€” making indicator checks, not just patching, the necessary remedial step. The nine-month span between disclosure and confirmed ransomware use, against a Shadowserver count that still finds nearly 9,000 unpatched instances online, makes this a standing example of the shrinking exploitation window measured against an unchanged remediation window. Australian and New Zealand SMB and MSP estates running Firebox firewalls should treat the KEV update as a prompt to verify patch state and hunt for the vendor's published indicators of attack. See cve-2025-14733.md.