CISA confirmed on September 9, 2026 that ransomware gangs are actively exploiting a WatchGuard Firebox flaw patched back in December 2025. The lesson has less to do with one firewall and more to do with how long “patch when convenient” stays convenient.
In December 2025, WatchGuard patched a critical flaw in its Firebox firewalls: CVE-2025-14733, an out-of-bounds write bug that allows unauthenticated remote code execution, reachable through the IKEv2 VPN or branch-office tunnel configuration that these firewalls expose by design. It was added to CISA's Known Exploited Vulnerabilities catalog that same month. For most businesses, a patch that old is background noise, something IT already handled, filed, and moved on from.
On September 9, 2026, roughly nine months later, CISA confirmed that ransomware gangs are now actively exploiting that same vulnerability in live campaigns. The security community's read on that gap is blunt: a KEV listing for an unauthenticated, internet-facing firewall RCE should be treated as the ransomware warning itself, on day one, regardless of whether ransomware activity has been publicly confirmed yet.
A firewall's VPN service is, by definition, always on and reachable from the internet. That's the entire point of a VPN endpoint. One security researcher described the exploitation as “low-complexity” specifically because of that always-on exposure. And patching alone may not be enough after the fact: because attackers were able to exfiltrate configuration data through this flaw, the recommended remediation includes rotating all appliance credentials and management database access, not just installing the update.
One WatchGuard CVE isn't really the point. The same pattern repeats across almost every internet-facing appliance: firewalls, VPN gateways, remote-access tools. A patch gets released, gets added to the federal government's confirmed-exploited list, and then sits for months in businesses that don't treat perimeter devices with the same urgency as a desktop update. Federal agencies work under a one-week remediation timeline for KEV-listed vulnerabilities on this class of device. That's a reasonable target for any business, not just federal contractors.
Patch management on the devices sitting at your network edge is exactly the kind of thing that's easy to defer and expensive to have deferred. That's the whole reason it's part of our managed support rather than something we assume gets handled.
Tell us what's going on and we'll quote a flat monthly number. No obligation.