September 14, 2026
Your Firewall Had a Patch in December. Ransomware Noticed.
CISA says ransomware gangs are exploiting a WatchGuard Firebox flaw patched last December. Thousands of small business firewalls remain exposed.
Chris Archer Sales & Marketing Director
Reviewed by Reade Taylor, Founder & President The patch shipped in December. Thousands of firewalls never got it.
On September 10, CISA confirmed that ransomware gangs are actively exploiting a critical flaw in WatchGuard Firebox firewalls, tracked as CVE-2025-14733. The fix has existed since December 2025. That is roughly nine months of patch availability, and according to BleepingComputer, nearly 9,000 Fireboxes were still sitting on the internet unpatched as of this month.
Back in December, more than 115,000 of these devices were exposed online. Most got patched. The ones that didn’t are now the target list, and attackers with ransomware to deploy are working through it.
Here’s why this one matters to small businesses specifically. Firebox is not a Fortune 500 firewall. It’s the box in the network closet of law offices, medical practices, contractors, property managers, and ten-person shops all over Florida. WatchGuard sells heavily through IT providers, which means most of these firewalls were installed by somebody’s IT company. Somebody was supposed to be updating them.
What the flaw actually does
CVE-2025-14733 is an out-of-bounds write bug in Fireware OS, the software that runs Firebox appliances. It affects Fireware 11.x, 12.x, and 2025.1 through 2025.1.3. An attacker doesn’t need a password or any account on the device. If the firewall has IKEv2 mobile VPN configured, which is a common setup for remote workers, the flaw can be exploited remotely in a low-complexity attack to run code on the firewall itself, per BleepingComputer’s report.
Think about what that means. The firewall is the device you bought to keep attackers out. Compromise it and the attacker isn’t picking a lock anymore. They own the door.
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog in December 2025, when the patch came out. What changed this week is the confirmation that exploitation now includes ransomware campaigns, as SC Media reported. That distinction matters. Plenty of exploited bugs get used for quiet spying or resale of access. When ransomware operators pick up an exploit, small businesses stop being bycatch and start being the catch.
The fixed versions are Fireware 12.11.6, 2025.1.4, and 12.5.15 for older appliances. If your firewall is running anything earlier, this applies to you.
There’s a pattern here too. SC Media notes this is the second unauthenticated remote code execution flaw in Firebox devices inside of about three months, following CVE-2025-9242, which affected more than 75,000 devices last fall. Edge devices like firewalls and VPN appliances have become one of the most reliable ways into a network, precisely because so many of them are installed once and never touched again.
Stuck on something like this right now?
Talk it through with a real US-based engineer, 24/7, no phone trees: (407) 587-0089.
Book a Free Strategy SessionNine months is not a patching backlog. It’s an unwatched network.
A firewall that misses one monthly update cycle happens. It shouldn’t, but it happens. A firewall that misses nine months of updates, including a critical fix that CISA flagged as actively exploited the same month it shipped, is a firewall nobody is looking at.
That’s the uncomfortable question buried in the 9,000 number. Every one of those unpatched Fireboxes belongs to an organization that either has no IT support, or has IT support that isn’t doing the job. If a business is paying a provider a monthly fee and that provider never applied a December patch to the single most security-critical device on the network, the monthly fee is buying a false sense of coverage.
Some honest questions worth asking your current provider this week. What version of Fireware are our firewalls running right now? When was the last firmware update applied, and is there a record of it? Who gets alerted when CISA adds something we run to the exploited-vulnerabilities list?
A competent provider answers those in one email, with dates. If the answer is silence, or a scramble, that tells you something you needed to know anyway. Firms in that position often assume moving providers is painful, so they stay. It’s a fixable problem, and we wrote up how a clean handover works on our page about switching IT providers, including what to do when the old provider drags their feet on handing over firewall credentials.
What to do this week
Patching is the whole game here, so the list is short.
First, find out if you have a WatchGuard Firebox at all. Plenty of owners genuinely don’t know what brand of firewall they run. It’s usually a red or black box near your internet equipment with the WatchGuard logo on it.
Second, get it on a fixed version. That’s 12.11.6, 2025.1.4, or 12.5.15 depending on the model. If the appliance is old enough that it can’t run supported firmware, it needs replacing, not another year of hoping.
Third, check whether IKEv2 mobile VPN is enabled. That’s the configuration the exploit path uses. If it’s on and nobody remembers why, turn it off until the firmware is current.
Fourth, assume checking once isn’t enough. This is the second Firebox emergency in three months, and it won’t be the last for edge devices generally. Firmware review belongs on a monthly schedule with the rest of patch management, which is exactly the sort of unglamorous work a managed security service exists to do. Our SOC team watches the CISA exploited-vulnerabilities feed daily and cross-references it against what clients actually run, an approach designed to catch this class of problem while it’s still a maintenance ticket instead of an incident.
And if a device like this does get popped, speed decides most of the outcome. Isolate the firewall, assume credentials that passed through it are burned, and get help fast. That’s the point where 24/7 support with a human on the phone stops being a marketing line and starts being the thing you actually needed.
The bigger lesson from a small box
Ransomware groups didn’t burn a zero-day for this. They didn’t need to. They waited for the long tail of businesses that never patch, and nine months later that tail was still 9,000 firewalls long. Attackers do the boring math, and unmanaged edge devices are the best return in the business right now.
Cyber Command manages firewalls, patching, and monitoring for businesses across Orlando, Tampa Bay, and Jacksonville from our headquarters in Winter Springs. If you don’t know what firmware your firewall is running, or your provider can’t tell you, call us at (407) 587-0089 or reach out here. A real engineer answers, and a firmware check takes minutes.
#CyberSecurity #ManagedIT #Ransomware #SmallBusiness #NetworkSecurity
This article is for general informational purposes only and is not legal, compliance, insurance, or other professional advice. Threats, technologies, and regulations change quickly; confirm current requirements with your own advisors before acting. See our full disclaimer.