CISA confirms ransomware gangs exploit an unauthenticated RCE in WatchGuard Firebox firewalls
On 10 September 2026, CISA updated the KEV entry for CVE-2025-14733 to confirm ransomware gangs are exploiting this unauthenticated RCE in the Firebox IKEv2 handler, 265 days after its first listing. Update Fireware OS and, if compromised, rotate every secret stored locally.
10 September 2026. CISA updates the KEV (Known Exploited Vulnerabilities) entry for CVE-2025-14733 with a new note: the flaw is now exploited in ransomware campaigns. 19 December 2025. The same flaw was first added to the KEV. September 2026. Between the two, 265 days elapsed. Why it matters: an unauthenticated remote-code-execution flaw in the perimeter firewall — the box that carries the VPN and the edge defense — has been patched for months, and ransomware gangs are exploiting it anyway.
An unauthenticated RCE in the IKEv2 service
CVE-2025-14733 is an out-of-bounds write in the iked process of Fireware OS, the daemon that handles IKEv2 key exchange on WatchGuard Firebox appliances. Rated CVSS 9.8, it lets a remote, unauthenticated attacker execute arbitrary code by sending a crafted IKEv2 packet to UDP port 500 or 4500.
The technical detail that matters is the trigger. The attack abuses abnormally large CERT payloads inside IKE_AUTH requests — WatchGuard explicitly cites these packets as an attack indicator. An out-of-bounds write in iked redirects execution into attacker-controlled code, with no prior authentication required. The firewall that was supposed to filter traffic becomes the attacker’s machine.
The exposure conditions are broader than they first appear. Vulnerable are appliances running a Fireware OS older than the patched versions that expose a Mobile User VPN over IKEv2, or a Branch Office VPN over IKEv2 with dynamic peers. The trap is that even configurations deleted in the past — a long-disabled Branch Office VPN with static peers — can leave the appliance vulnerable. The current state of the configuration is not enough to assess exposure: you have to reconstruct the history.
What attackers take, and how
The compromise cases documented by WatchGuard show a consistent pattern. After exploitation, the attacker encrypts the running configuration or packs it into a gzip archive along with the local administrator user database, then exfiltrates the lot to the same IP address as the attack. In other words, the immediate target is not encrypting the network, but stealing the secrets — configuration, local accounts, keys — that enable a deeper second pass.
That is an instructive shift in priority. A firewall concentrates exactly what you need to pivot: VPN pre-shared secrets, certificates, administrator account passwords, routes and rules. Stealing them is often worth more than encrypting data immediately, because they open the way to a durable and quiet compromise — precisely what ransomware operators want to maximize leverage.
WatchGuard notes that the ransomware-specific encryption steps have not been disclosed publicly. The CISA designation confirms use in ransomware campaigns but does not describe the final sequence. For a defender, the lesson is unchanged: a stolen configuration is already a compromise, even if no file has been encrypted yet.
Patched since December 2025, exploited in September 2026
The timeline is the most awkward part of the story. WatchGuard fixed CVE-2025-14733 in December 2025, in Fireware OS 2025.1.4, 12.11.6, 12.5.15 and 12.3.1-b728352. CISA added it to the KEV on 19 December 2025. Eight and a half months later, in September 2026, the agency has to spell out that the flaw is being exploited by ransomware.
That 265-day lag tells a structural truth about the edge-appliance market. Firewalls are among the hardest devices to update in production: a maintenance window interrupts the VPN and connectivity, validating a new image takes time, and admins hesitate to reboot equipment that «just works». The result: a critical flaw stays exploitable for months after a fix ships, and ransomware gangs have made a specialty of it.
The parallel with September 2026’s wider news is edifying. In the same month, CISA had to confirm ransomware exploitation of several other already-patched flaws — TeamCity, VMware vCenter — following the same pattern: a fix published, a KEV update, and gangs methodically working the list of known vulnerabilities to find the machines that were never updated. The KEV is no longer an alert; it is a worklist for attackers.
What to do, in order
The response combines an update and an incident response, in that order.
Update Fireware OS. Move to 2025.1.4, 12.11.6, 12.5.15 or 12.3.1-b728352 depending on your branch. Restricting exposure does not replace the update: as long as the vulnerable image runs, the IKEv2 service remains exploitable.
Look for signs of compromise. The iked diagnostic logs are the first source: certificate chains exceeding 8 certificates, CERT payloads larger than 2,000 bytes, and crashes or unresponsiveness in iked. Correlate them with outbound traffic from the appliance toward unusual addresses — exfiltration goes to the attacker’s IP, visible on the egress side even when the ingress looks normal.
Rotate the secrets. If compromise is confirmed or even suspected, WatchGuard recommends rotating every secret stored locally: pre-shared secrets, passwords, keys and certificates held in the Firebox. A stolen configuration contains all of them — leaving them unchanged keeps the door open after the intrusion.
# check the Fireware OS version
show version
# look for iked crashes or long certificate chains
show log | grep -i -E "iked|certificate chain|CERT payload" Verdict
If you run an exposed Firebox with an IKEv2 VPN, treat CVE-2025-14733 as a potential incident, not a routine patch: it is being exploited by ransomware, requires no authentication, and the history of deleted configurations can expose you without your knowing it. Update Fireware OS immediately, then hunt for signs of compromise and rotate local secrets in the same window. If you cannot patch today, restrict exposure of the IKEv2 service in the meantime — but understand that this does not neutralize the flaw. The broader lesson reaches beyond WatchGuard: an edge firewall patched eight months ago and still exploited by ransomware is proof that CISA’s KEV is now read as a target list, and that patch latency has become the true residual risk.
References
- BleepingComputer — CISA: WatchGuard RCE flaw now exploited in ransomware attacks (10 September 2026)
- WatchGuard PSIRT — Firebox iked Out of Bounds Write Vulnerability (CVE-2025-14733)
- CISA — Known Exploited Vulnerabilities Catalog, CVE-2025-14733 (added 19 December 2025)
- WatchGuard — Fireware versions 2025.1.4, 12.11.6, and 12.5.15 available now