The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that a critical remote code execution (RCE) vulnerability in WatchGuard Firebox firewalls, tracked as CVE-2025-14733, is now being exploited by ransomware groups. CISA added this flaw to its Known Exploited Vulnerabilities (KEV) catalog in December, at which point it was already being actively exploited.
The vulnerability is an out-of-bounds write issue that allows unauthenticated attackers to execute arbitrary code remotely with low complexity. It affects Fireware OS versions 11.x and later, including 11.12.4_Update1; 12.x and later, including 12.11.5; and versions 2025.1 through 2025.1.3.
When WatchGuard released patches for CVE-2025-14733 in December, the company stated that unpatched Firebox firewalls were vulnerable if configured to use IKEv2 VPN. However, WatchGuard also cautioned that devices might still be compromised even if vulnerable configurations had been removed, particularly if a branch office VPN to a static gateway peer remained configured. The vendor also confirmed active exploitation at that time and provided indicators of compromise to help customers detect potential breaches.
In December, the internet security watchdog group Shadowserver identified over 115,000 unpatched Firebox firewalls exposed online. Nine months later, nearly 9,000 of these instances reportedly remain unsecured.
CISA's update to its KEV catalog on Thursday specifically noted the involvement of ransomware gangs in exploiting CVE-2025-14733, though the agency did not release further details regarding these attacks. When the flaw was initially added to the KEV catalog in December, CISA issued a directive requiring U.S. federal agencies to secure their systems against it within one week, in accordance with Binding Operational Directive (BOD) 22-01.
This is not the first WatchGuard vulnerability to be highlighted by CISA. Two years prior, the agency mandated government agencies to patch another actively exploited WatchGuard flaw, CVE-2022-23176, which affected both Firebox and XTM firewalls. More recently, in September 2025, WatchGuard patched CVE-2025-9242, an RCE vulnerability in Firebox firewalls described as almost identical to CVE-2025-14733. CISA subsequently tagged CVE-2025-9242 as actively exploited one month later, with Shadowserver finding over 75,000 Firebox firewalls vulnerable to attacks at that time.
WatchGuard provides services to over 250,000 small and mid-sized businesses globally through a network of more than 17,000 security resellers and service providers.






