Security1 publisher2 min readPublished
CISA: Ransomware gangs exploiting WatchGuard Firebox flaw as 9,000 firewalls remain unpatched nine months later
CISA now flags CVE-2025-14733 as used in ransomware attacks, nine months after WatchGuard shipped the fix. Shadowserver's scans show the exposed population fell from more than 115,000 to nearly 9,000, and that remainder is the target set.
The Watch · Security desk

What happened
- CISA says ransomware gangs are now exploiting CVE-2025-14733, the critical WatchGuard Firebox flaw it first flagged as actively exploited in December.
- The bug is an out-of-bounds write that gives unauthenticated attackers remote code execution in low-complexity attacks against Fireware OS 11.x, 12.x and 2025.1 through 2025.1.3.
- Shadowserver counted more than 115,000 exposed unpatched Fireboxes in December and nearly 9,000 still unsecured nine months later.
- CISA added the flaw to its KEV catalog in December and gave US federal agencies one week to remediate under Binding Operational Directive 22-01.
- WatchGuard patched an almost identical Fireware flaw in September 2025, and a month after that fix shipped Shadowserver still found more than 75,000 vulnerable Fireboxes.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure WatchGuard sells to more than 250,000 small and mid-sized companies through more than 17,000 resellers and service providers, so the unpatched remainder sits mostly with organizations whose firewall is somebody else's contract and whose patch decision is somebody else's ticket.
- decision With no group named and no indicators published, intel-driven hunting has nothing to key on, which leaves firmware-version verification on every Firebox as the only action available to a defender this week.
- precedent An edge RCE picking up ransomware tooling nine months after the fix sets the expectation for the next KEV-listed firewall bug: the exploitable window is not the days before an advisory, it is however long the slowest operators take.
The IKEv2 wording is where remediation goes wrong. WatchGuard said in December that an unpatched Firebox is exploitable only when it is configured to use IKEv2 VPN, which reads as a scoping win until the rest of the sentence: an appliance whose vulnerable configuration has been deleted can still be compromised if a branch office VPN to a static gateway peer is still configured [5]. Anyone who took the first clause as an all-clear and stripped the config has a box that still answers.
Shadowserver's two counts bound the curve. About 92 percent of the December population was patched over the nine months, leaving roughly 8 percent [1]. That is a respectable drain rate for an edge appliance, and the residue is still large enough to be worth an affiliate's time. Measured against the remediation clock CISA set for federal agencies, the surviving boxes have now been reachable for about 39 times that window [2].
The tail is the pattern, not the exception. CISA had already pushed agencies onto WatchGuard firmware two years earlier for CVE-2022-23176 in Firebox and XTM firewalls [10], and the near-identical Fireware bug patched in September 2025 drained just as slowly. The same appliance family keeps producing unauthenticated remote code execution [3], and each time a five-figure population of it stays online past the fix.
What CISA published is the flag and nothing attached to it: no group, no tooling, no victim count, no indicators [2]. So the ransomware attribution here is CISA's assertion, carried in a KEV field, and it cannot be corroborated from the outside yet. That distinction matters less than it usually would. The exploit is unauthenticated, low complexity [3], and works against Fireware 11.x through 2025.1.3 [4], so whoever is using it does not need to be identified for the fix to be the same fix it was in December.
What to watch
- Whether CISA, WatchGuard, or an incident responder names the ransomware group and publishes indicators for the Firebox intrusions.
- Shadowserver's next Firebox scan, and whether the roughly 9,000 unpatched tail moves at all now that KEV carries the ransomware flag.
- Whether the almost identical September 2025 Fireware flaw also picks up ransomware exploitation, given how many appliances stayed vulnerable to it.