CISA: WatchGuard RCE flaw now exploited in ransomware attacks

CISA: WatchGuard RCE flaw now exploited in ransomware attacks
CISA has confirmed that ransomware gangs are exploiting CVE-2025-14733, a critical WatchGuard Firebox firewall flaw that allows unauthenticated remote code execution through an out-of-bounds write. WatchGuard and Shadowserver reported widespread exposure of unpatched Firebox devices, with tens of thousands still vulnerable online. #CVE202514733 #WatchGuardFirebox #Shadowserver #CISA

Keypoints

  • CVE-2025-14733 is a critical WatchGuard Firebox vulnerability.
  • The flaw can let unauthenticated attackers execute code remotely.
  • Fireware OS 11.x, 12.x, and 2025.1 branches are affected.
  • WatchGuard warned systems may remain at risk even after some settings are removed.
  • CISA says ransomware gangs are now using the flaw in attacks.

Read More: https://www.bleepingcomputer.com/news/security/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks/