INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
WatchGuard RCE Flaw Exploited in Ransomware Attacks
| 2026-09-10 11:00 CRITICAL HIGHExecutive Summary AI-generated
The exploitation of CVE-2025-14733 by groups of ransomware attackers has become a significant concern, with the vulnerability affecting different versions of Fireware OS. The incident highlights the ongoing threat posed by known vulnerabilities and the need for organizations to stay vigilant in protecting their systems against such attacks. As more instances continue to emerge without being patched, it is essential for companies like CISA to provide timely updates and support to mitigate the risk.
Technical Mitigations AI-generated
* Regularly update and patch Fireware OS: Ensure that all Fireware OS versions, including those affected by CVE-2025-14733 (CVE-2025-14734), are up-to-date with the latest security patches.
* Use secure VPN configurations: Configure firewalls to use IKEv2 VPNs instead of IKEv1, and ensure that any remote access connections are encrypted. This can help prevent attackers from exploiting CVE-2025-14733 on Fireboxes without a valid authentication token.
* Monitor for suspicious activity: Regularly monitor firewall logs and system activity for signs of unauthorized access or malicious behavior. Implement alerts and notifications to quickly respond to potential threats.
* Implement network segmentation: Segment the network into isolated zones, using firewalls and other security controls to limit the spread of malware and prevent attackers from exploiting CVE-2025-14733 on Fireboxes without a valid authentication token.
* Educate users about phishing and social engineering attacks: Ransomware gangs often use phishing and social engineering tactics to gain access to systems. Educating users about these types of attacks can help reduce the risk of falling victim to them, making it more difficult for attackers to exploit CVE-2025-14733 on Fireboxes without a valid authentication token.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-9242CVE-2025-9242
CVE-2022-23176CVE-2022-23176
CVE-2025-14733CVE-2025-14733
Target & Sectors
LA
governmentgovernment
Incident Timeline
September 2025
Threat actors are using a previously patched vulnerability in WatchGuard firewalls to target Firebox firewalls.
Click on any entity below to view its context and source!
organisation
CVE-2025-14733
More recently, in September 2025, WatchGuard
patched
an RCE vulnerability
(CVE-2025-9242) affecting Firebox firewalls and
almost identical to CVE-2025-14733.
organisation
CVE-2025-9242
More recently, in September 2025, WatchGuard
patched
an RCE vulnerability
(CVE-2025-9242) affecting Firebox firewalls and
almost identical to CVE-2025-14733.
2026/09/10
Grupos de ransomware están utilizando vulnerabilidades de WatchGuard Firebox para comprometer dispositivos.
Click on any entity below to view its context and source!
organisation
WatchGuard Firebox
Una vulnerabilidad crítica que afecta a los firewalls
WatchGuard Firebox
está siendo utilizada por grupos de ransomware para comprometer dispositivos vulnerables.
organisation
grupos de ransomware
Una vulnerabilidad crítica que afecta a los firewalls
WatchGuard Firebox
está siendo utilizada por grupos de ransomware para comprometer dispositivos vulnerables.
organisation
CVE-2025
ha actualizado la información sobre
CVE-2025-14733
, un fallo cuya explotación activa ya se conocía desde diciembre de 2025 y que ahora también ha sido relacionado con ataques de ransomware.
When it
released CVE-2025-14733 security patches
in December, WatchGuard said unpatched Firebox firewalls are vulnerable to attacks only if configured to use IKEv2 VPN, but noted they might still be compromised even if the vulnerable configurations have been deleted if a branch office VPN to a static gateway peer is still configured.
organisation
un
ha actualizado la información sobre
CVE-2025-14733
, un fallo cuya explotación activa ya se conocía desde diciembre de 2025 y que ahora también ha sido relacionado con ataques de ransomware.
organisation
WatchGuard RCE
WatchGuard RCE flaw now exploited in ransomware attacks.
organisation
CVE-2025-14733
Qué dispositivos WatchGuard están afectados
CVE-2025-14733 afecta a firewalls que ejecutan
Fireware OS 11.x y posteriores, 12.x y posteriores, así como las versiones comprendidas entre 2025.1 y 2025.1.3
.
infrastructure
2025.1
Qué dispositivos WatchGuard están afectados
CVE-2025-14733 afecta a firewalls que ejecutan
Fireware OS 11.x y posteriores, 12.x y posteriores, así como las versiones comprendidas entre 2025.1 y 2025.1.3
.
La vulnerabilidad se debe a una escritura fuera de límites y afecta a diferentes versiones de Fireware OS, incluidas las ramas 11.x, 12.x y 2025.1.
This vulnerability affects firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and 2025.1 through 2025.1.3.
infrastructure
2025.1.3
Qué dispositivos WatchGuard están afectados
CVE-2025-14733 afecta a firewalls que ejecutan
Fireware OS 11.x y posteriores, 12.x y posteriores, así como las versiones comprendidas entre 2025.1 y 2025.1.3
.
This vulnerability affects firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and 2025.1 through 2025.1.3.
organisation
WatchGuard
Qué dispositivos WatchGuard están afectados
CVE-2025-14733 afecta a firewalls que ejecutan
Fireware OS 11.x y posteriores, 12.x y posteriores, así como las versiones comprendidas entre 2025.1 y 2025.1.3
.
When it
released CVE-2025-14733 security patches
in December, WatchGuard said unpatched Firebox firewalls are vulnerable to attacks only if configured to use IKEv2 VPN, but noted they might still be compromised even if the vulnerable configurations have been deleted if a branch office VPN to a static gateway peer is still configured.
organisation
Fireware
Qué dispositivos WatchGuard están afectados
CVE-2025-14733 afecta a firewalls que ejecutan
Fireware OS 11.x y posteriores, 12.x y posteriores, así como las versiones comprendidas entre 2025.1 y 2025.1.3
.
This vulnerability affects firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and 2025.1 through 2025.1.3.
organisation
sin estar
Nueve meses después, cerca de
9.000 instancias continúan sin estar protegidas
frente a CVE-2025-14733.
organisation
Firebox
When it
released CVE-2025-14733 security patches
in December, WatchGuard said unpatched Firebox firewalls are vulnerable to attacks only if configured to use IKEv2 VPN, but noted they might still be compromised even if the vulnerable configurations have been deleted if a branch office VPN to a static gateway peer is still configured.
Cuando WatchGuard publicó los parches explicó que los Firebox sin actualizar eran vulnerables si estaban configurados para utilizar
IKEv2 VPN
.
organisation
IKEv2 VPN
When it
released CVE-2025-14733 security patches
in December, WatchGuard said unpatched Firebox firewalls are vulnerable to attacks only if configured to use IKEv2 VPN, but noted they might still be compromised even if the vulnerable configurations have been deleted if a branch office VPN to a static gateway peer is still configured.
infrastructure
11.12
This vulnerability affects firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and 2025.1 through 2025.1.3.
Entre las versiones expresamente mencionadas se encuentran 11.12.4_Update1 y 12.11.5.
infrastructure
12.11.5
This vulnerability affects firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and 2025.1 through 2025.1.3.
Entre las versiones expresamente mencionadas se encuentran 11.12.4_Update1 y 12.11.5.
organisation
después de publicarse los parches
La nueva advertencia resulta especialmente relevante porque, nueve meses después de publicarse los parches,
cerca de 9.000 dispositivos vulnerables continúan expuestos en Internet
.
organisation
Cerca de 9.000
Cerca de 9.000 firewalls siguen expuestos
El tiempo transcurrido desde la publicación del parche
organisation
el fallo
o grupos están aprovechando el fallo, cuáles son sus objetivos o qué ocurre después de conseguir acceso a los dispositivos.
organisation
la versión de Fireware OS
La prioridad para las organizaciones que utilicen WatchGuard Firebox es
comprobar inmediatamente la versión de Fireware OS e instalar las actualizaciones de seguridad disponibles
si todavía mantienen sistemas afectados.
organisation
Cuando WatchGuard
Cuando WatchGuard publicó los parches explicó que los Firebox sin actualizar eran vulnerables si estaban configurados para utilizar
IKEv2 VPN
.
organisation
IKEv2 VPN
.
Cuando WatchGuard publicó los parches explicó que los Firebox sin actualizar eran vulnerables si estaban configurados para utilizar
IKEv2 VPN
.
organisation
Sin
Sin embargo, existe un detalle importante para los administradores: eliminar posteriormente una configuración vulnerable no garantiza necesariamente que el dispositivo deje de estar expuesto.
organisation
deje de estar
Sin embargo, existe un detalle importante para los administradores: eliminar posteriormente una configuración vulnerable no garantiza necesariamente que el dispositivo deje de estar expuesto.
organisation
VPN de sucursal hacia
Según WatchGuard, determinados equipos podrían seguir siendo susceptibles de compromiso si permanece configurada una VPN de sucursal hacia un peer de gateway estático.
organisation
vía de entrada hacia
Los dispositivos perimetrales son objetivos especialmente atractivos porque pueden proporcionar una primera vía de entrada hacia las redes corporativas.
organisation
remota de código
No es la primera vulnerabilidad grave que afecta a Firebox
WatchGuard ya ha tenido que solucionar otros fallos de ejecución remota de código en sus dispositivos.
organisation
Shadowserver
Internet security watchdog group Shadowserver found
over 115,00 unpatched Firebox firewalls exposed online
in December, and
nearly 9,000 instances
remain unsecured after nine months.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tactical Metrics
Metrics
infrastructure
2025.1
Software Version
Click for context!
La vulnerabilidad se debe a una escritura fuera de límites y afecta a diferentes versiones de Fireware OS, incluidas las ramas 11.x, 12.x y 2025.1.
Qué dispositivos WatchGuard están afectados
CVE-2025-14733 afecta a firewalls que ejecutan
Fireware OS 11.x y posteriores, 12.x y posteriores, así como las versiones comprendidas entre 2025.1 y 2025.1.3
.
This vulnerability affects firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and 2025.1 through 2025.1.3.
Metrics
infrastructure
2025.1.3
Software Version
Qué dispositivos WatchGuard están afectados
CVE-2025-14733 afecta a firewalls que ejecutan
Fireware OS 11.x y posteriores, 12.x y posteriores, así como las versiones comprendidas entre 2025.1 y 2025.1.3
.
This vulnerability affects firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and 2025.1 through 2025.1.3.
Metrics
infrastructure
11.12
Software Version
Entre las versiones expresamente mencionadas se encuentran 11.12.4_Update1 y 12.11.5.
This vulnerability affects firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and 2025.1 through 2025.1.3.
Metrics
infrastructure
12.11.5
Software Version
Entre las versiones expresamente mencionadas se encuentran 11.12.4_Update1 y 12.11.5.
This vulnerability affects firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and 2025.1 through 2025.1.3.
Intelligence Sources
Bit Life Media
2026-09-10
BleepingComputer
2026-09-10
CISA: WatchGuard RCE flaw now exploited in ransomware attacks
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-11T06:03
Comprehensive Tactical Telemetry
Highly Correlated Entities
26x
organisation
Identified Entity
WatchGuard Firebox
entity
13x
attribution
Attributing Entity
KEV
authority
4x
infrastructure
Software Version
2025.1
version
3x
vulnerability
Exploited CVE
CVE-2025-14733
cve
3x
timeline
Temporal Reference
12.11.5
date
Contextual Telemetry
Context Block
15 METRICS
tactic
Cyber Operation Type
Ransomware
tactic
general metric
De
2,025
de
general metric
Ramas 11.X
2,025
ramas 11.x
general metric
Cerca Instancias
9
cerca instancias
target region
Target Country
Lao People's Democratic Republic
country
general metric
Detectó Más Firewalls
115
detectó más firewalls
general metric
Dispositivos
75
dispositivos
general metric
Pequeñas
250
pequeñas
general metric
Red Formada Por Más Distribuidores
17
red formada por más distribuidores
industry
Targeted Sector
Government
sector
general metric
Instances
9,000
instances
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
general metric
Firebox Firewalls
75,000
firebox firewalls
general metric
Small Sized Companies
250,000
small sized companies
general metric
Security Resellers
17,000
security resellers
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.