INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

WatchGuard RCE Flaw Exploited in Ransomware Attacks

| 2026-09-10 11:00 CRITICAL HIGH
Executive Summary AI-generated
The exploitation of CVE-2025-14733 by groups of ransomware attackers has become a significant concern, with the vulnerability affecting different versions of Fireware OS. The incident highlights the ongoing threat posed by known vulnerabilities and the need for organizations to stay vigilant in protecting their systems against such attacks. As more instances continue to emerge without being patched, it is essential for companies like CISA to provide timely updates and support to mitigate the risk.
Technical Mitigations AI-generated
* Regularly update and patch Fireware OS: Ensure that all Fireware OS versions, including those affected by CVE-2025-14733 (CVE-2025-14734), are up-to-date with the latest security patches. * Use secure VPN configurations: Configure firewalls to use IKEv2 VPNs instead of IKEv1, and ensure that any remote access connections are encrypted. This can help prevent attackers from exploiting CVE-2025-14733 on Fireboxes without a valid authentication token. * Monitor for suspicious activity: Regularly monitor firewall logs and system activity for signs of unauthorized access or malicious behavior. Implement alerts and notifications to quickly respond to potential threats. * Implement network segmentation: Segment the network into isolated zones, using firewalls and other security controls to limit the spread of malware and prevent attackers from exploiting CVE-2025-14733 on Fireboxes without a valid authentication token. * Educate users about phishing and social engineering attacks: Ransomware gangs often use phishing and social engineering tactics to gain access to systems. Educating users about these types of attacks can help reduce the risk of falling victim to them, making it more difficult for attackers to exploit CVE-2025-14733 on Fireboxes without a valid authentication token.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-9242CVE-2025-9242 CVE-2022-23176CVE-2022-23176 CVE-2025-14733CVE-2025-14733
Target & Sectors
LA
governmentgovernment
Incident Timeline
‎September 2025
Threat actors are using a previously patched vulnerability in WatchGuard firewalls to target Firebox firewalls.
organisation CVE-2025-14733
organisation CVE-2025-9242
‎2026/09/10
Grupos de ransomware están utilizando vulnerabilidades de WatchGuard Firebox para comprometer dispositivos.
organisation WatchGuard Firebox
organisation grupos de ransomware
organisation CVE-2025
organisation un
organisation WatchGuard RCE
organisation CVE-2025-14733
infrastructure 2025.1
infrastructure 2025.1.3
organisation WatchGuard
organisation Fireware
organisation sin estar
organisation Firebox
organisation IKEv2 VPN
infrastructure 11.12
infrastructure 12.11.5
organisation después de publicarse los parches
organisation Cerca de 9.000
organisation el fallo
organisation la versión de Fireware OS
organisation Cuando WatchGuard
organisation IKEv2 VPN .
organisation Sin
organisation deje de estar
organisation VPN de sucursal hacia
organisation vía de entrada hacia
organisation remota de código
organisation Shadowserver
organisation NFL
organisation CHANEL
Tactical Metrics
Metrics
infrastructure
‎2025.1
Software Version
Metrics
infrastructure
‎2025.1.3
Software Version
Metrics
infrastructure
‎11.12
Software Version
Metrics
infrastructure
‎12.11.5
Software Version
Intelligence Sources