CVE-2025-14733Active Exploitation(watchguard / firebox_m270)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Patch watchguard firebox_m270 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-12-26. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-787

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firebox_m270
  • firebox_m290
  • firebox_m295
  • firebox_m370

Threat summary

  • Active exploitation appears in 16 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 17 mentions across 5 observed days

What's happening

  • Active exploitation reported across 16 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 11 signals
  • Peaked 3d ago at 9 mentions (2026-09-10); latest day: 1
  • 17 total mentions across 5 days

Affected systems

Vendors
Products
firebox_m270firebox_m290firebox_m295firebox_m370firebox_m390firebox_m395firebox_m440firebox_m4600firebox_m470firebox_m4800

1 version affected across 39 products

Deep dive

Activity timeline17 mentions / 5d
02579Mentions · 2026-06-20: 1Mentions · 2026-09-10: 9Mentions · 2026-09-11: 5Mentions · 2026-09-12: 1Mentions · 2026-09-13: 1PoC Mentioned / Linked · 2026-09-10: 1Exploit Tool / Code · 2026-09-10: 1Active Exploitation · 2026-06-20: 1Active Exploitation · 2026-09-10: 9Active Exploitation · 2026-09-11: 5Active Exploitation · 2026-09-12: 1Patch / Workaround · 2026-09-10: 7Patch / Workaround · 2026-09-11: 4Technical Details · 2026-09-10: 7Technical Details · 2026-09-11: 3Technical Details · 2026-09-12: 106-2009-1009-1109-1209-13
Signal classification1 categories
Active Exploitation
16100.0%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-06-201
Active Exploitation1
2026-09-109
Active Exploitation9
2026-09-115
Active Exploitation5
2026-09-121
Active Exploitation1
Full discourse17 posts
  • SafeBreach@safebreach
    Active Exploitation

    CISA just confirmed ransomware crews are exploiting CVE-2025-14733. Unauthenticated, pre-auth, reachable over IKEv2 VPN—the exact services a firewall exposes. @SafeBreach Offensive Security Engineer explains why patch availability was never the gap: https://hubs.ly/Q04xd-xz0

    Post summary

    CISA confirmed ransomware crews are actively exploiting CVE‑2025‑14733 over IKEv2 VPN; patch availability was never the issue.

    01020201
    2.5K followersView on X
  • Decryption Digest ®@DecryptionDigst
    Active Exploitation

    WatchGuard Firebox: 9K VPNs unpatched. CVE-2025-14733 CVSS 9.8 pre-auth IKEv2 RCE. Ransomware exploiting. CISA KEV Sept 10. https://www.decryptiondigest.com/blog/watchguard-firebox-cve-2025-14733-ransomware-exploitation #WatchGuard #CVE202514733 #Ransomware https://t.co/4jrZlOSLNw

    Post summary

    The blog confirms that the WatchGuard Firebox vulnerability CVE‑2025‑14733 is being actively exploited by ransomware, with CISA identifying it as a KEV.

    10010102
    33 followersView on X
  • CCB Alert@CCBalert
    Active Exploitation

    Warning: #WatchGuard reports #CVE-2025-14733 in #Fireware is #ActivelyExploited. More info at: https://psirt.watchguard.com/CVE-2025-14733/ #Patch #Patch #Patch

    Post summary

    The post alerts that CVE-2025-14733 in WatchGuard Fireware is actively exploited, provides a vendor link for more information, and notes a patch.

    02000305
    7.2K followersView on X
  • TwitGri@TwitGri
    Active Exploitation

    ⚠️ WatchGuard : CISA confirme désormais l’usage de CVE-2025-14733 dans des attaques ransomware. RCE pré-auth sur Firebox ; ~9 000 équipements resteraient exposés. Mettez à jour Fireware et vérifiez les IoC WatchGuard. #Cyber #Ransomware

    Post summary

    CISA confirms CVE‑2025‑14733 is being actively exploited in ransomware attacks against WatchGuard Firebox devices, enabling remote code execution before authentication and exposing roughly 9,000 units, prompting an urgent Fireware patch.

    0001059
    36 followersView on X
  • Xavier Rivera@XavierRiveraX
    Active Exploitation

    WatchGuard Firebox CVE-2025-14733 is now confirmed in ransomware attacks, per CISA's KEV update. The December out-of-bounds write lets unauthenticated attackers run code on Fireware OS when IKEv2 VPN is enabled, and some static branch-office VPN peers stay exposed even after config cleanup. Patch remaining Firebox appliances and check WatchGuard IoCs; Shadowserver still sees nearly 9,000 online.

    Post summary

    CISA confirms that WatchGuard Firebox CVE-2025-14733 is actively exploited in ransomware attacks, with ongoing vulnerabilities and a patch recommended for all remaining appliances.

    00010116
    604 followersView on X
  • Frontiera Tech@FrontieraTechIT
    Active Exploitation

    🛡️ CYBER BULLETIN | 2026/09/10 🚨 1. CISA adds Cisco, Citrix and Fortinet flaws to the KEV list Cisco Secure FMC has a maximum-severity auth bypass (CVE-2026-20079) that gives unauthenticated attackers root on the firewall manager. CISA also flagged Citrix NetScaler and a Fortinet code-execution bug. U.S. federal agencies must patch the highest-risk ones by Sept 12. 2. WatchGuard Firebox RCE now used in ransomware CISA confirmed ransomware groups are exploiting CVE-2025-14733, a remote code-execution flaw in Firebox firewalls. Patches have been out for months, but thousands of devices are still sitting on the internet. 3. Record Microsoft Patch Tuesday — then a new Defender zero-day September updates fix roughly 970 vulnerabilities, including two already exploited 0-days. Right after the release, a researcher published “ShieldCrash,” a Microsoft Defender exploit that still grants SYSTEM on fully patched Windows.

    Post summary

    The bulletin reports that several high‑severity CVEs—Cisco Secure FMC, Citrix NetScaler, Fortinet, WatchGuard Firebox, and a Microsoft Defender zero‑day—are being actively exploited in the wild, underscores the need for immediate patching, and notes that new exploit code (“ShieldCrash”) remains effective against patched systems.

    10000151
    87 followersView on X
  • ADK Cyber@ADKCyber

    New on the blog — When the Firebox Still Listens: WatchGuard and CVE-2025-14733. CISA now flags CVE-2025-14733 as ransomware-used. Inventory internet-facing Fireboxes, move to fixed Fireware, verify leftover IKEv2 exposure, and hunt vendor IoCs. https://www.adkcyber.com/blogs/when-the-firebox-still-listens-watchguard-cve-2025-14733

    0000077
    95 followersView on X
  • ActuX@ActuX_off
    Active Exploitation

    🚨🔥 CYBERSÉCURITÉ — DES GANGS RANSOMWARE EXPLOITENT DÉSORMAIS UNE FAILLE CRITIQUE DES PARE-FEU WATCHGUARD Nouveau développement autour de CVE-2025-14733 : la CISA classe désormais son exploitation comme liée à des campagnes ransomware. La faille était déjà exploitée, mais son utilisation par des groupes d’extorsion constitue une escalade importante. ➡️ Produit : WatchGuard Firebox / Fireware OS ➡️ Gravité : CVSS 9,3/10 ➡️ Exploitation à distance sans authentification ➡️ Exécution de code arbitraire possible sur le pare-feu ➡️ Les configurations VPN IKEv2 sont particulièrement concernées. WatchGuard a observé des attaquants exfiltrer notamment la configuration active des Firebox ainsi que la base locale des comptes administrateurs. ⚠️ Particularité importante : certains équipements peuvent rester vulnérables même après suppression d’une ancienne configuration VPN dynamique, selon leur configuration actuelle. ✅ Pour un équipement potentiellement compromis, installer le correctif ne suffit pas : WatchGuard recommande également de renouveler les secrets stockés sur le Firebox. ❓ Les pare-feu et passerelles VPN sont-ils devenus l’un des principaux moyens d’accès initial des groupes ransomware ? Source : CISA / WatchGuard PSIRT #Cybersecurite #WatchGuard #Firebox #Ransomware #VPN #CVE202514733 #CyberSecurity #Infosec

    Post summary

    Ransomware gangs are actively exploiting CVE‑2025‑14733 in WatchGuard firewalls, with CISA confirming in‑the‑wild attacks and recommending patching plus secret renewal.

    0000055
    233 followersView on X
  • 高野久|サイバーセキュリティ@DIVERTtokyo
    Active Exploitation

    VPNの脆弱性が、実際のランサムウェア侵入に使われています。 今度はWatchGuard Fireboxです。 米CISA(サイバーセキュリティ・インフラセキュリティ庁)は、CVE-2025-14733が実際に悪用されているとして、KEV(既知悪用脆弱性カタログ)に追加しました。 WatchGuardも、この脆弱性を悪用した侵入後にランサムウェアが展開された事例を確認しています。 しかも重要なのは、「パッチを当てれば、それで終わり」とは限らないこと。 すでに侵入されていた場合、 ・認証情報は盗まれていないか ・不審なアカウントは作られていないか ・内部へ横展開されていないか まで確認する必要があります。 ちょうど先日、「VPNは導入して終わりではなく、何年も脆弱性を追い、更新し続けられるかが重要」 という記事を書きました。 今回のWatchGuardの事例は、その問題がまさに現実のものだと示しています。 VPNは会社を守る入口であると同時に、インターネットから常に見られている入口でもあります。 WatchGuard Firebox、CVE-2025-14733、CISA KEV、そしてランサムウェアまで、現時点で分かっていることを整理しました。 https://sbom-security.jp/news/watchguard-firebox-cve-2025-14733-ransomware #サイバーセキュリティ #WatchGuard #VPN #ランサムウェア #CVE

    Post summary

    CISA has listed CVE‑2025‑14733 as actively exploited against WatchGuard Firebox, fueling ransomware attacks; patching alone is insufficient and organizations must verify for intrusion and lateral movement.

    0000076
    22 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows ransomware groups exploiting CVE-2025-14733 to compromise WatchGuard firewalls, then pivoting through internal networks for lateral movement and data exfiltration. Nearly 9,000 devices remain vulnerable despite patches being available for nine months. Runtime segmentation helps limit blast radius when perimeter defenses fail. #ZeroTrust #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/cisa-watchguard-cve-2025-14733-ransomware-attacks

    Post summary

    The post reports active ransomware exploitation of CVE‑2025‑14733 on WatchGuard firewalls, with many devices still vulnerable despite patches, and recommends runtime segmentation as a containment strategy.

    0000084
    2.0K followersView on X
  • RichTechGuy@richtechguy
    Active Exploitation

    CISA: WatchGuard Firebox CVE-2025-14733 (RCE) now confirmed in ransomware use. Unpatched IKEv2-exposed devices remain a target—verify patch level and residual VPN config risk. https://www.bleepingcomputer.com/news/security/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks/

    Post summary

    WatchGuard Firebox RCE CVE-2025-14733 is being actively exploited in ransomware attacks; users are advised to check patch levels and VPN configuration to mitigate risk.

    0000069
    355 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    CISA says ransomware gangs are exploiting CVE-2025-14733 in WatchGuard Firebox, a critical RCE flaw affecting Fireware OS 11.x, 12.x, and 2025.1. Tens of thousands of devices may still be exposed. #WatchGuard #CISA #RCE https://www.hendryadrian.com/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks/

    Post summary

    CISA confirms ransomware gangs are exploiting CVE‑2025‑14733 on WatchGuard Firebox devices, representing an active exploitation scenario with a critical remote‑code‑execution flaw affecting multiple Fireware OS versions.

    00000213
    4.7K followersView on X
  • NEXSIGHT@NEXSIGHTNEWS
    Active Exploitation

    CISAがWatchGuard Firebox CVE-2025-14733のランサムウェア悪用を確認 — VPN経由の認証なしRCE、侵害の痕跡確認と更新を https://cyber.nexsight.co/articles/2026/09/10/cisa-watchguard-firebox-ransomware-cve-2025-14733-2026-09-10/

    Post summary

    CISA reports that ransomware actors have exploited CVE‑2025‑14733 in WatchGuard Firebox devices via unauthenticated RCE over VPN, with evidence of ongoing attacks and a call for updates.

    0000065
    66 followersView on X
  • SecureChap@SecureChap
    Active Exploitation

    WatchGuard Firebox owners running Fireware OS just got handed unauthenticated RCE over IKEv2. CVE-2025-14733 is an out-of-bounds write reachable when IKEv2 VPN is enabled or a branch office VPN to a static gateway peer stays configured. Hits 11.x, 12.x and 2025.1 through 2025.1.3. CISA added it to KEV after confirmed in-the-wild exploitation; WatchGuard pushed patches and IOCs the same month. Can't patch yet? Disable the exposure fast: Web UI: VPN > Mobile VPN > IKEv2 > uncheck Enable, then VPN > Branch Office VPN > select the static peer > Edit > uncheck Enable. CLI: `no vpn ikev2 enable` `no vpn branch-office-vpn peer <name> enable` After the change, verify with `show vpn ikev2 status` and `show vpn branch-office-vpn` plus a quick packet capture on UDP 500/4500.

    Post summary

    CISA listed CVE‑2025‑14733 in its KEV after it was confirmed being exploited over IKEv2, and WatchGuard released patches and workarounds. The post provides both technical details of the vulnerability and mitigation steps.

    0000065
    172 followersView on X
  • ᴊ@ᴄǫғ•s「🦑」🤖@ita_ipo
    Active Exploitation

    🐦 🚨 Cisco Secure FMC auth bypass (CVE-2026-20079) actively exploited for pre-auth root access — patch now. Ransomware gangs also hitting WatchGuard Firebox (CVE-2025-14733). MS Patch Tuesday fixed 974 flaws, incl. 2 exploited 0-days. #infosec #CVE #ransomware

    Post summary

    Cisco Secure FMC authentication bypass (CVE-2026-20079) is being actively exploited for pre‑auth root access, a patch has been released, and ransomware groups are also targeting WatchGuard Firebox (CVE‑2025‑14733). Microsoft Patch Tuesday addressed 974 flaws, including two zero‑days.

    0000066
    219 followersView on X
  • Arnaud Wallon@arwallon
    Active Exploitation

    Des ransomwares s'attaquent aux pare-feu WatchGuard, confirme la CISA La CISA confirme que des ransomwares exploitent la faille CVE-2025-14733 des pare-feu WatchGuard Firebox. Versions corrigées, données volées et gestes à faire. https://numeribrain.com/posts/watchguard-firebox-ransomware-cve-2025-14733

    Post summary

    CISA confirms ransomware is actively exploiting CVE‑2025‑14733 on WatchGuard Firebox firewalls; patched versions are available but data theft has occurred.

    0000037
    359 followersView on X
  • CompuChris@compuchris
    Active Exploitation

    WatchGuard Firebox Zero-Day (CVE-2025-14733) Actively Exploited: Threat Intelligence and Mitigation Guidance - Rescana #CISO https://news.google.com/rss/articles/CBMiwwFBVV95cUxOQUFNVTdrWEZkOU9YNGhibHBOTHIxSlV5REZjN2NrSW1yTTY4aWdpSnZscmJWMlVacHd0QlBycW5zZ25kWEk4YVVROHQxNHdtR3pfaEl5YU9IU05xU24wSWtVX09IUWpYNkJWLWpRUUVJU2oyNG44M3M5UXI4V1NxbHRTYmJtRGVsZzVxZGxsZU1IMVZoQURFbENYZ201ZEczMUdUYTRJWkxRZ1U4TUdPcmU4QmRIMUxSRlRlMzF2T2txVFk?oc=5

    Post summary

    WatchGuard Firebox vulnerability CVE-2025-14733 is currently being exploited in the wild, with threat intelligence and mitigation guidance provided.

    0000038
    1.7K followersView on X
CPE platform detail39 entries

39 of 39 entries

PartVendorProductVersionTarget SWTarget HW
HWwatchguardfirebox_m270---
HWwatchguardfirebox_m290---
HWwatchguardfirebox_m295---
HWwatchguardfirebox_m370---
HWwatchguardfirebox_m390---
HWwatchguardfirebox_m395---
HWwatchguardfirebox_m440---
HWwatchguardfirebox_m4600---
HWwatchguardfirebox_m470---
HWwatchguardfirebox_m4800---
HWwatchguardfirebox_m495---
HWwatchguardfirebox_m5600---
HWwatchguardfirebox_m570---
HWwatchguardfirebox_m5800---
HWwatchguardfirebox_m590---
HWwatchguardfirebox_m595---
HWwatchguardfirebox_m670---
HWwatchguardfirebox_m690---
HWwatchguardfirebox_m695---
HWwatchguardfirebox_nv5---
HWwatchguardfirebox_t115-w---
HWwatchguardfirebox_t125---
HWwatchguardfirebox_t125-w---
HWwatchguardfirebox_t145---
HWwatchguardfirebox_t145-w---
HWwatchguardfirebox_t15---
HWwatchguardfirebox_t185---
HWwatchguardfirebox_t20---
HWwatchguardfirebox_t25---
HWwatchguardfirebox_t35---
HWwatchguardfirebox_t40---
HWwatchguardfirebox_t45---
HWwatchguardfirebox_t55---
HWwatchguardfirebox_t70---
HWwatchguardfirebox_t80---
HWwatchguardfirebox_t85---
HWwatchguardfireboxcloud---
HWwatchguardfireboxv---
OSwatchguardfireware---

Explore more