logo

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

ID: 0132516b-c049-585d-a7ba-068304f3bd3a

STIX ID: report--0132516b-c049-585d-a7ba-068304f3bd3a

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-09-10

Date Updated: 2026-09-10

Author: Sergiu Gatlan

...
...

CISA confirms ransomware gangs are actively exploiting CVE-2025-14733, a critical out-of-bounds write leading to remote code execution in WatchGuard Firebox firewalls; WatchGuard released patches and IOCs while Shadowserver reported over 115,000 exposed devices (with ~9,000 still unpatched), and CISA added the flaw to its Known Exploited Vulnerabilities catalog requiring federal remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.