Back to feed

CISA confirms WatchGuard Firebox bug now exploited in ransomware campaigns

2 min
CISA confirms WatchGuard Firebox bug now exploited in ransomware campaigns

This digest was compiled by AI from multiple sources — links to the originals are below.

CISA confirmed on Sept. 9 that an out-of-bounds write vulnerability in WatchGuard Firebox, added to its Known Exploited Vulnerabilities catalog in December, is now being exploited in ransomware campaigns. Security experts say the nine-month gap between catalog listing and ransomware exploitation is typical, but warn that teams should not delay patching. The flaw, CVE-2025-14733, was initially listed with ransomware status 'Unknown' and silently changed to 'Known' this week.

Key Facts

  • CISA added CVE-2025-14733 to the Known Exploited Vulnerabilities catalog in December 2025 with the ransomware field set to 'Unknown'.
  • CISA silently flipped the ransomware field for CVE-2025-14733 to 'Known' this week, according to Jacob Krell of Suzu Labs.
  • WatchGuard shipped an almost identical pre-auth remote code execution vulnerability, CVE-2025-9242, three months before CVE-2025-14733.
  • In 2025, CISA quietly updated the ransomware flag on 59 vulnerabilities, with gaps ranging from one day to over 1,300 days.
  • WatchGuard confirmed attackers were exfiltrating configs and management databases from affected Firebox appliances.

CISA Confirmation

The Cybersecurity and Infrastructure Security Agency confirmed on Sept. 9 that an out-of-bounds write bug in WatchGuard Firebox is now being used in ransomware campaigns. The vulnerability, CVE-2025-14733, was added to the Known Exploited Vulnerabilities catalog in December 2025. At the time of listing, the ransomware field was set to 'Unknown,' and CISA changed it to 'Known' this week without an announcement. Jacob Krell, senior director of secure AI solutions and cybersecurity at Suzu Labs, confirmed the nine-month KEV-to-ransomware escalation is normal.

Expert Warnings

Collin Hogue-Spears, senior director of solution management at Black Duck, said security leaders must treat a KEV listing for an unauthenticated, internet-facing firewall RCE as the ransomware warning itself. Hogue-Spears advised applying the federal one-week remediation lock to every internet-facing appliance CVE that enters the catalog, regardless of the ransomware field. Krell said teams running WatchGuard Firebox appliances should patch to Fireware 12.11.6, 2025.1.4, or 12.5.15 and rotate every credential on the appliance. WatchGuard confirmed attackers were exfiltrating configs and management databases, making credential rotation necessary even after patching.

Pattern of Vulnerabilities

Krell noted that WatchGuard shipped an almost identical pre-auth remote code execution vulnerability, CVE-2025-9242, three months before CVE-2025-14733. Adrian Culley, offensive security engineer at iCounter, said CVE-2025-14733 mirrors CVE-2025-9242's characteristics closely enough that WatchGuard's patch cadence looks like 'whack-a-mole' against a class of bug in the same code path. In 2025, CISA quietly updated the ransomware flag on 59 vulnerabilities, with gaps ranging from one day to over 1,300 days and no announcement when any of them changed.

2 sources

Time · lag behind first