FR
live

CISA confirms ransomware gangs exploit an unauthenticated RCE in WatchGuard Firebox firewalls

On 10 September 2026, CISA updated the KEV entry for CVE-2025-14733 to confirm ransomware gangs are exploiting this unauthenticated RCE in the Firebox IKEv2 handler, 265 days after its first listing. Update Fireware OS and, if compromised, rotate every secret stored locally.

A long concrete wall covered in a grid of identical anthracite tiles, one single amber tile freshly replaced and sitting slightly proud of the rest.

10 September 2026. CISA updates the KEV (Known Exploited Vulnerabilities) entry for CVE-2025-14733 with a new note: the flaw is now exploited in ransomware campaigns. 19 December 2025. The same flaw was first added to the KEV. September 2026. Between the two, 265 days elapsed. Why it matters: an unauthenticated remote-code-execution flaw in the perimeter firewall — the box that carries the VPN and the edge defense — has been patched for months, and ransomware gangs are exploiting it anyway.

An unauthenticated RCE in the IKEv2 service

CVE-2025-14733 is an out-of-bounds write in the iked process of Fireware OS, the daemon that handles IKEv2 key exchange on WatchGuard Firebox appliances. Rated CVSS 9.8, it lets a remote, unauthenticated attacker execute arbitrary code by sending a crafted IKEv2 packet to UDP port 500 or 4500.

The technical detail that matters is the trigger. The attack abuses abnormally large CERT payloads inside IKE_AUTH requests — WatchGuard explicitly cites these packets as an attack indicator. An out-of-bounds write in iked redirects execution into attacker-controlled code, with no prior authentication required. The firewall that was supposed to filter traffic becomes the attacker’s machine.

The exposure conditions are broader than they first appear. Vulnerable are appliances running a Fireware OS older than the patched versions that expose a Mobile User VPN over IKEv2, or a Branch Office VPN over IKEv2 with dynamic peers. The trap is that even configurations deleted in the past — a long-disabled Branch Office VPN with static peers — can leave the appliance vulnerable. The current state of the configuration is not enough to assess exposure: you have to reconstruct the history.

What attackers take, and how

The compromise cases documented by WatchGuard show a consistent pattern. After exploitation, the attacker encrypts the running configuration or packs it into a gzip archive along with the local administrator user database, then exfiltrates the lot to the same IP address as the attack. In other words, the immediate target is not encrypting the network, but stealing the secrets — configuration, local accounts, keys — that enable a deeper second pass.

That is an instructive shift in priority. A firewall concentrates exactly what you need to pivot: VPN pre-shared secrets, certificates, administrator account passwords, routes and rules. Stealing them is often worth more than encrypting data immediately, because they open the way to a durable and quiet compromise — precisely what ransomware operators want to maximize leverage.

WatchGuard notes that the ransomware-specific encryption steps have not been disclosed publicly. The CISA designation confirms use in ransomware campaigns but does not describe the final sequence. For a defender, the lesson is unchanged: a stolen configuration is already a compromise, even if no file has been encrypted yet.

Patched since December 2025, exploited in September 2026

The timeline is the most awkward part of the story. WatchGuard fixed CVE-2025-14733 in December 2025, in Fireware OS 2025.1.4, 12.11.6, 12.5.15 and 12.3.1-b728352. CISA added it to the KEV on 19 December 2025. Eight and a half months later, in September 2026, the agency has to spell out that the flaw is being exploited by ransomware.

That 265-day lag tells a structural truth about the edge-appliance market. Firewalls are among the hardest devices to update in production: a maintenance window interrupts the VPN and connectivity, validating a new image takes time, and admins hesitate to reboot equipment that «just works». The result: a critical flaw stays exploitable for months after a fix ships, and ransomware gangs have made a specialty of it.

The parallel with September 2026’s wider news is edifying. In the same month, CISA had to confirm ransomware exploitation of several other already-patched flaws — TeamCity, VMware vCenter — following the same pattern: a fix published, a KEV update, and gangs methodically working the list of known vulnerabilities to find the machines that were never updated. The KEV is no longer an alert; it is a worklist for attackers.

What to do, in order

The response combines an update and an incident response, in that order.

Update Fireware OS. Move to 2025.1.4, 12.11.6, 12.5.15 or 12.3.1-b728352 depending on your branch. Restricting exposure does not replace the update: as long as the vulnerable image runs, the IKEv2 service remains exploitable.

Look for signs of compromise. The iked diagnostic logs are the first source: certificate chains exceeding 8 certificates, CERT payloads larger than 2,000 bytes, and crashes or unresponsiveness in iked. Correlate them with outbound traffic from the appliance toward unusual addresses — exfiltration goes to the attacker’s IP, visible on the egress side even when the ingress looks normal.

Rotate the secrets. If compromise is confirmed or even suspected, WatchGuard recommends rotating every secret stored locally: pre-shared secrets, passwords, keys and certificates held in the Firebox. A stolen configuration contains all of them — leaving them unchanged keeps the door open after the intrusion.

bash
# check the Fireware OS version
show version

# look for iked crashes or long certificate chains
show log | grep -i -E "iked|certificate chain|CERT payload"

Verdict

If you run an exposed Firebox with an IKEv2 VPN, treat CVE-2025-14733 as a potential incident, not a routine patch: it is being exploited by ransomware, requires no authentication, and the history of deleted configurations can expose you without your knowing it. Update Fireware OS immediately, then hunt for signs of compromise and rotate local secrets in the same window. If you cannot patch today, restrict exposure of the IKEv2 service in the meantime — but understand that this does not neutralize the flaw. The broader lesson reaches beyond WatchGuard: an edge firewall patched eight months ago and still exploited by ransomware is proof that CISA’s KEV is now read as a target list, and that patch latency has become the true residual risk.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

The Carbonato botnet turns exposed Docker daemons into Telegram-controlled AI agents

ThreatDown researchers reconstructed the Carbonato botnet, which compromises Docker daemons exposed on port 2375 and installs the open-source Hermes Agent framework with nothing but its persona file rewritten. Close port 2375, move to rootless or TLS, and revoke any AI API key sitting on a potentially affected host.

US soldier sentenced to 70 months for extorting ten telecom firms

On 28 September 2026, Cameron John Wagenius, aka kiberphant0m, was sentenced to 70 months in prison for hacking and extorting at least ten technology and telecommunications companies from his military base. The case is a reminder that insider threat and SSH brute-forcing remain an entry path as effective as any zero-day.

← Back to the feed

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss