FR
live

Ransomware gangs now exploit the unauthenticated IKEv2 RCE in WatchGuard Firebox firewalls

CISA updated its KEV entry on September 10, 2026 to confirm that CVE-2025-14733, an unauthenticated RCE in the WatchGuard Firebox iked process patched back in December 2025, is now used in ransomware attacks. With nearly 9,000 Fireboxes still exposed online, check your Fireware OS version and hunt for the indicators of compromise before the encryption starts.

A steel security turnstile with its arm removed from a row of identical turnstiles, leaving a person-sized gap, one small amber beacon glowing above the opening.

December 2025. WatchGuard patches CVE-2025-14733, an unauthenticated RCE in the iked process of Fireware OS. September 9, 2026. Shadowserver still counts nearly 9,000 Firebox firewalls exposed online, nine months after the fix. September 10, 2026. CISA updates its KEV entry: the flaw is now exploited by ransomware gangs. The message is not “patch this CVE” — it has been patched for months. The message is “your perimeter VPN gateway may still be open, and the price of forgetting just moved from espionage to encryption”.

A perimeter RCE patched nine months ago

The flaw is an out-of-bounds write (CWE-787) in the iked process, the daemon that handles IKEv2 key exchange for VPNs. A remote attacker, with no authentication at all, can send a malicious IKE_AUTH request and run arbitrary code on the firewall. CISA describes the attack as low complexity, and WatchGuard assigned it a CVSS 9.5 — the critical range.

What makes it vicious is the surface it covers. It affects two distinct configurations: Mobile VPN over IKEv2 and branch-office VPN over IKEv2 to a dynamic gateway peer. Even if you deleted those configurations in the past, a branch-office VPN to a static gateway peer still present can keep the box vulnerable. In other words, a device’s configuration history can leave it exposed with nothing visible to signal it.

The affected versions span most of the Fireware OS fleet: the 11.x branch (up to and including 11.12.4 Update1), the 12.x branch (up to and including 12.11.5) and 2025.1 (up to 2025.1.3). The fix lands in Fireware OS 2025.1.4, 12.11.6, 12.5.15 and 12.3.1-b728352 depending on the model.

What attackers do once they are inside

WatchGuard documents two variants of post-exploit activity observed in the wild. In the first, the attacker encrypts and exfiltrates the active configuration file to the same IP address the attack originates from. In the second, the attacker builds a gzip archive containing both the active configuration and the local management user database, and exfiltrates that archive to the same address.

The second variant is the more alarming one downstream. A Firebox configuration concentrates the VPN connection secrets — pre-shared keys, certificates, passwords — and the local admin database hands over the device’s administrative accounts. Once both are out, the attacker is not just walking through the perimeter: they hold enough to replay tunnels and administer the box remotely, even after the patch. That is precisely why WatchGuard tells operators to rotate all locally stored secrets on any device suspected of compromise.

The shift to ransomware changes the nature of the risk. Back in December, the documented exploitation was mostly espionage — steal the config, listen, leave. Now CISA confirms that groups are using the flaw to encrypt data. For an SMB whose Firebox is the single front door to the network, the scenario is no longer “we are being watched”, it is “we are being shut down”.

Nine months later, nearly 9,000 firewalls still exposed

The most damning number comes from Shadowserver. In December 2025, the organization counted over 115,000 vulnerable Fireboxes exposed online. Nine months later, nearly 9,000 instances remain unpatched. That is a drop of more than 90%, and yet it is still a whole field of targets for a ransomware campaign that only needs to reach an open IKEv2 service.

Why do these boxes stay unpatched? Because a firewall does not patch like a workstation. A Firebox reboot drops every VPN tunnel in the business: remote sites, remote workers, sometimes telephony. The maintenance window has to be scheduled, approved, and usually executed at night. In an SMB without a dedicated team, updating a firewall that “still works” is postponed indefinitely — until an attacker decides the schedule instead.

The pattern is systematic at WatchGuard. In September 2025, the vendor patched CVE-2025-9242, an RCE “almost identical” to this one, and Shadowserver later counted over 75,000 boxes exposed. Two years earlier, CVE-2022-23176 was exploited by Russian state hackers. Same vendor, same class of device, same lesson left unlearned.

How to tell whether your Firebox is already compromised

WatchGuard publishes precise indicators of attack, applicable only to unpatched devices. Two log signatures stand out.

First, an abnormally long certificate chain in the authentication request, visible at the default logging level:

text
iked[2938]: (203.0.113.1<->203.0.113.2) Received peer certificate chain is longer than 8. Reject this certificate chain

Second, an abnormally large CERT payload in the IKE_AUTH request, visible at the “info” logging level:

text
iked (203.0.113.1<->203.0.113.2) "IKE_AUTH request" message has 6 payloads [ IDi(sz=21) CERT(sz=3000) SA(sz=44) TSi(sz=24) TSr(sz=24) N(sz=8) ]

A CERT payload above 2,000 bytes is a strong indicator. Add two behavioral signals: an iked process that hangs (interrupting key negotiations and re-keys) and an iked crash with a fault report. Finally, WatchGuard publishes a list of known attacker IP addresses — any outbound connection from the box to one of them is a sign of compromise, checked separately from inbound connections.

Verdict

CVE-2025-14733 is not an ordinary patch alert: the fix has existed since December 2025, and what changed on September 10, 2026 is the escalation of exploitation into ransomware. The flaw itself is a blunt reminder that the VPN edge remains the most exposed surface of an SMB, and that the real risk is not the vulnerability but the maintenance debt that keeps it open for nine months.

If you run a Firebox, check your Fireware OS version immediately: anything on 11.x, 12.x before 12.11.6, or 2025.1 before 2025.1.4 must be updated, even if you think you removed the vulnerable VPN configurations. Then hunt the indicators: oversized CERT payloads, long certificate chains, outbound connections to the published IPs. If a signal shows up, rotate every locally stored secret — not just the admin password.

If you cannot patch right away and only use branch-office VPNs to static gateway peers, apply WatchGuard’s documented workaround while you schedule the window. But do not treat it as a fix: limiting exposure never replaces the update, and an exposed firewall is a target waiting its turn.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

Passkey-themed phishing drains corporate Microsoft 365 accounts

Microsoft documents attacks in which ShinyHunters and Helix-linked gangs impersonate the help desk to steer employees toward passkey-themed phishing pages, then exfiltrate Microsoft 365 data. The defense rests less on the passkey itself than on phishing-resistant authentication and session revocation.

← Back to the feed

Type at least two characters.

navigate open esc dismiss