LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
cve recordhighexploited in the wildzero day3 of 3 cataloguesransomwareexploit reported

CVE-2025-14733

WatchGuard · Firebox · WatchGuard Firebox Out of Bounds Write Vulnerability

· Added to CISA KEV
CVSS
Severityhigh
Weakness
EPSS26.5%97.9th percentile
Exploited3 KEV sources
Ransomware useKnown
Federal fix dueDec 26, 2025
patch window

Called exploited the same day it was disclosed.

Measured from the CVE publication date to the earliest of 3 KEV catalogues that list it.

The life of this vulnerability

  1. CVE published
  2. First KEV listingsame day
  3. Last sighting4mo

Gaps are compressed to equal steps. The elapsed time is printed under each.

Which catalogues call it exploited

Sources3 of 3
Listings differ by0 d
Strongest claimconfirmed

3 catalogues list it. CIRCL aggregates the others and is shown but not counted.

Public exploitation evidence

8 public reports collected from VulnCheck and CIRCL, first on Dec 19, 2025. Each links to its original source. We have not verified them.

Description

WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.

Required action (CISA)

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

References

← Back to the CVE Tracker

Our coverage of CVE-2025-14733

CVE-2025-14733critical

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

Ransomware groups are actively exploiting a critical vulnerability in WatchGuard Firebox firewalls, according to CISA. The flaw, tracked as CVE-2025-14733, allows unauthenticated attackers to execute remote code with low complexity. While WatchGuard released patches in December, a significant number of devices remain vulnerable, with thousands still exposed online.