A critical vulnerability in WatchGuard Firebox firewalls has also entered the scope of ransomware operations. Confirmation comes from the U.S. Cybersecurity and Infrastructure Security Agency, which updated its entry in the catalog of known exploited vulnerabilities, indicating that the flaw is being used in campaigns tied to data encryption and extortion.

The issue is identified as CVE-2025-9242 and affects Fireware OS, the operating system of Firebox appliances. It is a flaw that can allow unauthenticated remote code execution: a characteristic that makes it particularly sensitive for a product deployed at the corporate network perimeter. CISA had already added it to its Known Exploited Vulnerabilities Catalog in December, noting that evidence of real-world exploitation existed. The update now clarifies that ransomware groups are also among those leveraging it.

Why a vulnerable firewall provides attackers with valuable access

Firewalls and VPN gateways are recurring targets because they are designed to receive external connections and, in many organizations, represent a direct path to internal resources. A flaw that allows attackers to take control of one of these devices can provide them with an initial foothold without having to convince an employee to open an attachment or pre-emptively steal credentials through a fake website.

In the case of an RCE vulnerability, code execution on the device can turn into access to a part of the network that the firewall is supposed to protect. From there, the next phase depends on the campaign: environmental reconnaissance, lateral movement, data exfiltration, ransomware deployment, or a combination of these activities. CISA's advisory does not attribute the attacks to a specific group, nor does it describe a single intrusion chain, but it is enough to shift the operational priority assigned to the flaw.

Vulnerabilities listed in the KEV catalog are not simply high-severity technical flaws. They are weaknesses for which US authorities have observed active exploitation. When this advisory is extended to ransomware campaigns, the risk to organizations goes far beyond appliance downtime: business continuity, potential data exfiltration, and the financial and legal fallout of an incident all come into play.

The timeline: first active exploitation, then the ransomware link

WatchGuard had released security updates to patch CVE-2025-9242. In December, CISA added the vulnerability to the KEV list, urging organizations to remediate within the deadlines set for US federal agencies. However, the catalog is widely used well beyond the US public sector as a benchmark for prioritizing patch management.

The latest update does not change the nature of the flaw, but it adds a critical factor to the risk assessment: ransomware actors are actively exploiting it. In practice, this narrows the window for treating the update as routine scheduled maintenance. Any Internet-facing device still running a vulnerable release requires an immediate review of its exposure and the application of the fixes provided by the vendor.

The flaw carries a critical CVSS rating, scoring 9.3 out of 10. This figure must be weighed alongside real-world attack evidence: high scores do not automatically mean a vulnerability is being weaponized at scale, whereas the KEV catalog exists precisely to pinpoint when a threat has become operational. In this case, both conditions are met.

Top-priority verification steps

The first step for administrators managing WatchGuard firewalls is to inventory all Firebox appliances, verify the installed version of Fireware OS, and compare it against the patched releases specified in the vendor’s security advisory. While the update should be carefully planned to prevent disruption, it should not be postponed until the regular monthly patch cycle, especially for directly Internet-exposed appliances.

Simply installing the patch does not necessarily resolve an intrusion that has already occurred. Organizations discovering they were vulnerable during the period of known exploitation should therefore examine the available logs on the firewall and connected systems, looking for unusual activity, anomalous logins, and unexpected configuration changes. The depth of the analysis depends on the appliance's exposure, enabled services, and log retention capabilities.

  • identify all Firebox appliances, including those managed by branch offices or third-party vendors;
  • apply the patched versions of Fireware OS specified by WatchGuard for the model in use;
  • verify that the Internet-exposed attack surface is limited to strictly necessary services;
  • review logs, configurations, and administrative credentials if signs of unauthorized access emerge;
  • involve the incident response team whenever a pre-patch compromise cannot be ruled out.

It is crucial to avoid two frequent mistakes. The first is regarding the update as proof that no damage was done: a patch prevents future exploitation of the specific flaw, but does not automatically remove tools or modifications left behind by an attacker. The second is focusing exclusively on the network device. If the firewall was used as an entry point, the investigation must extend to assets reachable from the appliance and systems managing identity, backups, and virtual infrastructure.

A warning sign for managing exposed vulnerabilities

The incident confirms an established pattern in ransomware attacks: perimeter devices remain a prime target when they harbor unpatched vulnerabilities. The availability of exploits, public exposure, and the ability to achieve remote execution are factors that rapidly drive criminal interest, often before organizations have finished rolling out updates.

For IT and security managers, the WatchGuard case suggests treating KEV notifications as an indicator distinct from traditional severity metrics. A reliable inventory of internet-connected assets, procedures for urgent updates, and telemetry retained long enough to support an investigation are elements that reduce response time when a flaw transitions from a vendor advisory to a ransomware vector.

No additional public details have been released by CISA regarding the ransomware campaigns exploiting CVE-2025-9242. The very lack of a full description of the techniques employed makes it prudent to assume that attempts may continue and that the priority must be eliminating exposure. For WatchGuard users, the question is no longer whether the flaw can be exploited: US authorities say it already is, including for ransomware purposes.

Sources