WatchGuard Firebox CVE-2025-14733: CISA Flags Ransomware Use on a Stubborn Edge RCE

By George Bailey   Published: 09/13/26   Updated: 09/13/26   2 min read

What Changed

On September 10, 2026, BleepingComputer reported that CISA updated its KEV catalog to mark CVE-2025-14733 as known to be used in ransomware campaigns. CISA had already listed the flaw as actively exploited in December 2025; Thursday’s update raises the stakes without publishing new campaign detail.

CVE-2025-14733 is an out-of-bounds write in the Fireware OS iked process. A remote unauthenticated attacker can execute arbitrary code. It affects Mobile User VPN with IKEv2 and Branch Office VPN using IKEv2 (dynamic gateway peer). WatchGuard warns residual risk can remain even after those configs are deleted if a branch office VPN to a static gateway peer is still configured.

Affected: Fireware OS 11.10.2–11.12.4_Update1, 12.0–12.11.5, 2025.1–2025.1.3 (plus 12.5.x T15/T35 through 12.5.14 per vendor matrices). Fixed: 2025.1.4, 12.11.6, 12.5.15 (T15/T35), 12.3.1_Update4 (FIPS). 11.x is end of life — no fix; replace or remove from exposure.

Shadowserver counted 115,000+ unpatched internet-exposed Fireboxes at disclosure; nearly 9,000 remain exposed ~nine months later (BleepingComputer / Shadowserver reporting).

Why This Matters Operationally

Fireboxes terminate VPN and sit on the perimeter. Unauthenticated RCE there is ransomware-grade initial access: config and credential theft, then a path inside. Nine months after patches, thousands still answer the internet — and CISA’s ransomware flag means “we’ll get to it in the next change window” is not a strategy.

What Defenders Should Verify First

Source Context

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.