CISA: WatchGuard RCE flaw now exploited in ransomware attacks
Ransomware gangs are actively exploiting a serious flaw in WatchGuard Firebox firewalls to break into networks and encrypt files. This flaw lets attackers run their own commands on your firewall, giving them full control.
- Report priority
- High
- Group
- CISA: WatchGuard RCE flaw now exploited in
What is known
- Attackers send a specially crafted request to the WatchGuard Firebox firewall's web interface.
- The firewall's code fails to properly check this request, letting attackers run commands on the firewall itself.
- This lets them move deeper into your network and encrypt files for ransom.
What to do
Check your installed WatchGuard Firebox firmware version. If your version is before 23.8.1, you are affected. WatchGuard has released a patch to fix this issue.
Update your WatchGuard Firebox firmware to version 23.8.1 or later immediately. You can download the latest firmware from the WatchGuard Support Portal. After updating, verify the new version in About > System Information to confirm the fix is applied.
Reported details
Ransomware groups like LockBit and BlackCat have been observed using this flaw to break into networks protected by WatchGuard Firebox firewalls. Once inside, they encrypt files and demand payment to restore access.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December.