CISA: WatchGuard Firebox RCE Flaw Now Exploited in Ransomware Attacks
U.S. agency confirms active exploitation of critical firewall vulnerability, urges immediate patching

Key Takeaways
- CISA confirmed that ransomware gangs are exploiting a critical RCE vulnerability in WatchGuard Firebox firewalls.
- The vulnerability was first flagged as actively exploited in December and is now being used in ransomware attacks.
- Immediate patching to the latest firmware is strongly recommended.
- Organizations should disable unused services and monitor for signs of compromise.
- CISA has issued a Binding Operational Directive for federal agencies to patch promptly.
Quick answers
- What happened?
- CISA has confirmed that ransomware gangs are exploiting a critical remote code execution vulnerability in WatchGuard Firebox firewalls, which was first flagged as actively exploited in December. Organizations using affected devices are urged to apply patches immediately and follow mitigation guidance.
- Which products are affected?
- Firebox
- What should defenders do?
- Organizations should apply the latest WatchGuard firmware updates immediately. Disable unused services and features on Firebox devices. Restrict management access to trusted networks. Monitor for unusual activity and indicators of compromise. Follow CISA's Binding Operational Directive and WatchGuard's security advisory for detailed guidance.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are actively exploiting a critical remote code execution (RCE) vulnerability in WatchGuard Firebox firewalls. The flaw, which was initially flagged by CISA as actively exploited in December, has now been observed in ransomware attacks, raising the urgency for organizations to patch and mitigate.
CISA's confirmation underscores the severity of the vulnerability, which could allow attackers to gain full control of affected firewall devices. Successful exploitation could lead to network compromise, lateral movement, data exfiltration, and deployment of ransomware.
WatchGuard has released security advisories and firmware updates to address the vulnerability. CISA has also issued a Binding Operational Directive (BOD) requiring federal agencies to patch affected systems promptly. Organizations are advised to apply the latest firmware updates, disable unused services, and monitor for indicators of compromise.
The specific ransomware group(s) involved have not been publicly identified, and detailed exploit mechanics have not been fully disclosed. However, the confirmed active exploitation in ransomware campaigns elevates the risk for all WatchGuard Firebox users.
Organizations should prioritize patching, review their security configurations, and ensure that firewall management interfaces are not exposed to the internet unless necessary. Regular backups and incident response readiness are also recommended to mitigate the impact of potential ransomware attacks.
Security Details
A critical remote code execution vulnerability in WatchGuard Firebox firewalls is being actively exploited by ransomware gangs. The flaw allows attackers to execute arbitrary code on the device, potentially leading to full system compromise. CISA has confirmed active exploitation, and while specific technical details are not fully disclosed, the impact is severe.
Affected products
Firebox
Mitigation
Organizations should apply the latest WatchGuard firmware updates immediately. Disable unused services and features on Firebox devices. Restrict management access to trusted networks. Monitor for unusual activity and indicators of compromise. Follow CISA's Binding Operational Directive and WatchGuard's security advisory for detailed guidance.
Sources
BleepingComputer
CISA: WatchGuard RCE flaw now exploited in ransomware attacks
Sep 10, 2026 · 09:10
Original link
Related Security News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The maintainers of the official MCP Python SDK disclosed a security vulnerability that could allow a malicious server to trick applications into divulging OAuth credentials. The issue affects the handling of client secrets, authorization codes, and PKCE proof keys when communicating with token endpoints.

Former US Air Force Members Sentenced to Prison for Business Email Compromise Scams
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. The sentencing, reported by BleepingComputer in September 2026, concluded a federal case targeting individuals who abused their military backgrounds to conduct financially motivated email fraud. The attacks spanned multiple years prior to sentencing, though specific victim counts and total financial losses were not detailed in the reporting. The case underscores the legal consequences of using military credentials and training for cyber-enabled fraud.

