CISA: WatchGuard RCE flaw now exploited in ransomware attacks

Published September 10, 2026

Ransomware gangs are actively exploiting a serious flaw in WatchGuard Firebox firewalls to break into networks and encrypt files. This flaw lets attackers run their own commands on your firewall, giving them full control.

Report priority
High
Group
CISA: WatchGuard RCE flaw now exploited in

What is known

  • Attackers send a specially crafted request to the WatchGuard Firebox firewall's web interface.
  • The firewall's code fails to properly check this request, letting attackers run commands on the firewall itself.
  • This lets them move deeper into your network and encrypt files for ransom.

What to do

Check your installed WatchGuard Firebox firmware version. If your version is before 23.8.1, you are affected. WatchGuard has released a patch to fix this issue.

Update your WatchGuard Firebox firmware to version 23.8.1 or later immediately. You can download the latest firmware from the WatchGuard Support Portal. After updating, verify the new version in About > System Information to confirm the fix is applied.

Reported details

Ransomware groups like LockBit and BlackCat have been observed using this flaw to break into networks protected by WatchGuard Firebox firewalls. Once inside, they encrypt files and demand payment to restore access.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December.