CISA confirms ransomware groups exploiting WatchGuard Firebox flaw CVE-2025-14733
CISA has updated its Known Exploited Vulnerabilities catalog to warn that ransomware operators are now actively abusing a critical remote-code-execution bug in WatchGuard Firebox firewalls, first flagged as exploited back in December. The flaw, an out-of-bounds write bug affecting multiple Fireware OS versions, lets unauthenticated attackers run code remotely, particularly on devices configured for IKEv2 VPN. Shadowserver data shows nearly 9,000 Firebox devices remain unpatched online nine months after fixes were released.