LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
CVE-2025-14733critical

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

Ransomware groups are actively exploiting a critical vulnerability in WatchGuard Firebox firewalls, according to CISA. The flaw, tracked as CVE-2025-14733, allows unauthenticated attackers to execute remote code with low complexity. While WatchGuard released patches in December, a significant number of devices remain vulnerable, with thousands still exposed online.

zeroday.news ·

Photo: Jakez (CC BY-SA 3.0) via Wikimedia Commons

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that a critical remote code execution (RCE) vulnerability in WatchGuard Firebox firewalls, tracked as CVE-2025-14733, is now being exploited by ransomware groups. CISA added this flaw to its Known Exploited Vulnerabilities (KEV) catalog in December, at which point it was already being actively exploited.

The vulnerability is an out-of-bounds write issue that allows unauthenticated attackers to execute arbitrary code remotely with low complexity. It affects Fireware OS versions 11.x and later, including 11.12.4_Update1; 12.x and later, including 12.11.5; and versions 2025.1 through 2025.1.3.

When WatchGuard released patches for CVE-2025-14733 in December, the company stated that unpatched Firebox firewalls were vulnerable if configured to use IKEv2 VPN. However, WatchGuard also cautioned that devices might still be compromised even if vulnerable configurations had been removed, particularly if a branch office VPN to a static gateway peer remained configured. The vendor also confirmed active exploitation at that time and provided indicators of compromise to help customers detect potential breaches.

In December, the internet security watchdog group Shadowserver identified over 115,000 unpatched Firebox firewalls exposed online. Nine months later, nearly 9,000 of these instances reportedly remain unsecured.

CISA's update to its KEV catalog on Thursday specifically noted the involvement of ransomware gangs in exploiting CVE-2025-14733, though the agency did not release further details regarding these attacks. When the flaw was initially added to the KEV catalog in December, CISA issued a directive requiring U.S. federal agencies to secure their systems against it within one week, in accordance with Binding Operational Directive (BOD) 22-01.

This is not the first WatchGuard vulnerability to be highlighted by CISA. Two years prior, the agency mandated government agencies to patch another actively exploited WatchGuard flaw, CVE-2022-23176, which affected both Firebox and XTM firewalls. More recently, in September 2025, WatchGuard patched CVE-2025-9242, an RCE vulnerability in Firebox firewalls described as almost identical to CVE-2025-14733. CISA subsequently tagged CVE-2025-9242 as actively exploited one month later, with Shadowserver finding over 75,000 Firebox firewalls vulnerable to attacks at that time.

WatchGuard provides services to over 250,000 small and mid-sized businesses globally through a network of more than 17,000 security resellers and service providers.

vulnerabilities in this storyCVE-2025-14733CVE-2022-23176CVE-2025-9242
watchguardrceransomwarecisavulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.