WatchGuard has revealed two critical vulnerabilities in its Windows WatchGuard Agent, which could allow unauthenticated attackers to execute arbitrary code on affected endpoints. These vulnerabilities, tracked as CVE-2026-57910 and CVE-2026-57909, have CVSS v4.0 scores of 9.3 and 9.4, respectively.
Both issues impact WatchGuard Agent versions earlier than 1.25.13.0000. If exploited, these vulnerabilities could give an attacker complete control over the compromised host, potentially granting SYSTEM-level privileges on Windows systems.
Authentication Bypass Enables Code Execution
CVE-2026-57910 is an improper authentication vulnerability affecting the WatchGuard Agent’s UDP discovery and command service.
This flaw allows an unauthenticated attacker with network access to trigger the agent’s TaskExecute event handler, causing the service to download and execute an attacker-controlled program.
Since the WatchGuard Agent typically runs with elevated privileges, successful exploitation could result in arbitrary code execution as root or SYSTEM, depending on the platform and deployment.
In practical terms, this means an attacker could install malware, maintain persistence, access sensitive files, alter security configurations, or use the compromised endpoint as a foothold for lateral movement.
WatchGuard has categorized this flaw under several weakness categories:
- CWE-306: Missing Authentication for Critical Function
- CWE-347: Improper Verification of Cryptographic Signature
- CWE-494: Download of Code Without Integrity Check
This vulnerability presents a high-risk scenario: a remotely accessible service accepts commands without sufficient authentication and retrieves and executes code without proper validation of its integrity or origin.
The second vulnerability, CVE-2026-57909, is a path traversal flaw that also allows unauthenticated remote code execution. Unlike CVE-2026-57910, exploitation of this vulnerability requires the attacker to be on an adjacent network, rather than just having general network access.
WatchGuard notes that a successful attack could result in a complete loss of the affected endpoint protection component’s confidentiality, integrity, and availability.
This issue is mapped to CWE-94, which involves improper control of code generation, and to CWE-306, which relates to missing authentication for a critical function.
While the requirement for adjacent network access reduces exposure compared to vulnerabilities that are exposed to the internet, it still poses a significant risk in enterprise environments.
Attackers who gain access to a Wi-Fi network, a VPN segment, a compromised internal system, or a poorly isolated subnet could target unpatched WatchGuard Agent installations.
As of August 25, 2026, WatchGuard has stated that it is not aware of any exploitation of either vulnerability in the wild. However, the absence of public exploitation should not be seen as a reason to delay remediation, especially since both vulnerabilities allow unauthenticated code execution.
Organizations should upgrade their WatchGuard Agent to version 1.25.13.0000 or later. Specific fixes for CVE-2026-57910 include versions 1.17.02.0000 and 1.17.21.0000, while CVE-2026-57909 specifically requires version 1.25.13.0000.
Security teams should review the versions of the deployed Agent, prioritize systems that are exposed or internally reachable, and monitor for unusual UDP discovery traffic, unexpected TaskExecute activity, and suspicious binary downloads or process launches originating from the WatchGuard Agent service.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

