Vulnerability
Published 2026-09-10
Verified 2026-09-19

WatchGuard Firebox iked RCE (CVE-2025-14733) now used in ransomware (CISA)

WatchGuard PSIRT CVE-2025-14733 is an out-of-bounds write in the Fireware OS iked process that can let a remote unauthenticated attacker execute code. It affects mobile-user VPN with IKEv2 and branch-office VPN using IKEv2 with a dynamic gateway peer; boxes that previously had those configs may still be vulnerable if a branch-office VPN to a static gateway peer remains. WatchGuard rates it CVSS 4.0 9.3 (AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N) and has observed in-the-wild exploitation, including config exfiltration variants. Fixed builds include Fireware OS 2025.1.4, 12.11.6, 12.5.15 and 12.3.1-b728352 (plus rotate locally stored secrets after confirmed compromise). CISA had already flagged active exploitation; BleepingComputer (10 September 2026) reports CISA now also confirms ransomware gangs are exploiting the same CVE. Shadowserver previously saw >115k exposed Fireboxes in December and nearly 9k still unpatched months later. Distinct from desk card watchguard-fireware-iked-20260827 (August 2026 five-critical advisory set). Primary: WatchGuard PSIRT; wire: BleepingComputer; KEV: CISA catalog for CVE-2025-14733.

Product
WatchGuard Fireware OS (Firebox iked / IKEv2 VPN)
Versions
Affected trains include Fireware OS >=2025.1 & <2025.1.4; 12.x before 12.11.6 / 12.5.15 / 12.3.1-b728352 (and earlier 11.x/12.x ranges cited in vendor/wire); fixed: 2025.1.4, 12.11.6, 12.5.15, 12.3.1-b728352
CVSS
Exploited in Australia?
unknown
Patch to
Upgrade Fireware OS to 2025.1.4 / 12.11.6 / 12.5.15 / 12.3.1-b728352 as applicable; hunt IoAs; rotate secrets if compromise suspected

Primary: WatchGuard PSIRT — CVE-2025-14733 · Vendor: CISA KEV — CVE-2025-14733 · CVE: CVE-2025-14733 · BleepingComputer — ransomware use (10 Sep 2026)

vulnerabilities network