What Changed
On September 10, 2026, BleepingComputer reported that CISA updated its KEV catalog to mark CVE-2025-14733 as known to be used in ransomware campaigns. CISA had already listed the flaw as actively exploited in December 2025; Thursday’s update raises the stakes without publishing new campaign detail.
CVE-2025-14733 is an out-of-bounds write in the Fireware OS iked process. A remote unauthenticated attacker can execute arbitrary code. It affects Mobile User VPN with IKEv2 and Branch Office VPN using IKEv2 (dynamic gateway peer). WatchGuard warns residual risk can remain even after those configs are deleted if a branch office VPN to a static gateway peer is still configured.
Affected: Fireware OS 11.10.2–11.12.4_Update1, 12.0–12.11.5, 2025.1–2025.1.3 (plus 12.5.x T15/T35 through 12.5.14 per vendor matrices). Fixed: 2025.1.4, 12.11.6, 12.5.15 (T15/T35), 12.3.1_Update4 (FIPS). 11.x is end of life — no fix; replace or remove from exposure.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Shadowserver counted 115,000+ unpatched internet-exposed Fireboxes at disclosure; nearly 9,000 remain exposed ~nine months later (BleepingComputer / Shadowserver reporting).
Why This Matters Operationally
Fireboxes terminate VPN and sit on the perimeter. Unauthenticated RCE there is ransomware-grade initial access: config and credential theft, then a path inside. Nine months after patches, thousands still answer the internet — and CISA’s ransomware flag means “we’ll get to it in the next change window” is not a strategy.
What Defenders Should Verify First
- Confirm Fireware is on a fixed build above; EOL 11.x boxes need replacement, not hope.
- Do not assume “we disabled IKEv2” equals safe — check static branch-office VPN peers per WatchGuard’s residual-risk note.
- Hunt with WatchGuard’s published IoCs (IKE_AUTH CERT payloads,
ikedanomalies, unexpected outbound connections). - If the appliance was exposed, rotate all secrets stored on the Firebox and treat the device as potentially fully compromised.
Source Context
- WatchGuard PSIRT: WGSA-2025-00027 (CVE-2025-14733)
- BleepingComputer: CISA — WatchGuard RCE now exploited in ransomware attacks (Sep 10, 2026)
- Horizon3: CVE-2025-14733 analysis
- CISA Known Exploited Vulnerabilities Catalog
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.