Called exploited the same day it was disclosed.
Measured from the CVE publication date to the earliest of 3 KEV catalogues that list it.
The life of this vulnerability
- CVE published
- First KEV listingsame day
- Last sighting4mo
Gaps are compressed to equal steps. The elapsed time is printed under each.
Which catalogues call it exploited
- CISA KEVUS federallisted Dec 19, 2025
- EUVDENISA, European Unionlisted Dec 19, 2025
- VulnCheck KEVcommercial researchlisted Dec 19, 2025
- CIRCLaggregator, mirrors the abovelisted Dec 19, 2025, not counted
3 catalogues list it. CIRCL aggregates the others and is shown but not counted.
Public exploitation evidence
- reported exploitationctrlaltintel.com/research/Qilin/
- reported exploitationwww.loginsoft.com/reports/annually/vulnerability-intelligenc
- reported exploitationwww.recordedfuture.com/blog/december-2025-cve-landscape
- reported exploitationhorizon3.ai/attack-research/vulnerabilities/cve-2025-14733/
- reported exploitationhs-45734016.f.hubspotemail.net/hubfs/45734016/Global%20Threa
- reported exploitationarcticwolf.com/resources/blog/cve-2025-14733/
8 public reports collected from VulnCheck and CIRCL, first on Dec 19, 2025. Each links to its original source. We have not verified them.
Description
WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.
Required action (CISA)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
