CyberSecurityNews

Critical WatchGuard API Vulnerabilities Enables Command Execution Attacks


WatchGuard has disclosed three security vulnerabilities affecting WatchGuard AP devices, including two critical flaws that could allow attackers to gain unauthenticated access and execute commands on vulnerable access points.

Organizations using WatchGuard AP firmware earlier than version 3.4.8 should apply the available update immediately. The vulnerabilities were published on September 28, 2026, and affect WatchGuard AP versions from 1.0 through 3.4.7.

WatchGuard addressed all three issues in version 3.4.8. The most serious issue, tracked as CVE-2026-86102, carries a CVSS v4 score of 9.3. The vulnerability is an OS command injection flaw in the internal management API service.

An attacker with network access to a vulnerable WatchGuard AP could send crafted input to trigger arbitrary shell command execution on the underlying operating system.

No authentication or user interaction is required, making the bug especially dangerous where the affected API service is reachable from untrusted networks.

WatchGuard API Vulnerabilities

A second critical vulnerability, CVE-2026-101891, is also rated 9.3. It stems from improper access control in an internal API service on WatchGuard access points. The flaw allows an unauthenticated attacker with network access to access functionality that should be protected.

This issue could provide a path for attackers to interact with internal management capabilities and potentially support follow-on compromise attempts against the device or connected environment.

The third vulnerability, CVE-2026-87969, is a high-severity command injection issue with a CVSS v4 score of 8.6. Unlike the two critical flaws, exploitation requires authenticated administrator privileges.

A malicious or compromised administrator account could supply crafted input through the diagnostic command-line interface and execute arbitrary operating system commands on the WatchGuard AP.

Command injection vulnerabilities are particularly serious in network appliances because compromised access points can become a foothold inside enterprise networks.

Attackers may use command execution to collect configuration data, modify device settings, deploy persistence mechanisms, intercept network traffic, or attempt lateral movement toward other systems.

Devices exposed through management networks, remote-access paths, or poorly segmented wireless infrastructure may face greater risk.

Security teams should first identify all deployed WatchGuard AP devices and verify their firmware versions. Prioritize upgrading devices running a release earlier than 3.4.8.

Administrators should also restrict access to AP management interfaces and internal API services. They should be reachable only from trusted administrative networks.

Organizations should review access logs, administrative activity, diagnostic CLI usage, and configuration changes for signs of unexpected activity. They should also rotate administrative credentials if there is any indication that an AP management account may have been exposed.

Network segmentation can reduce the impact of a compromised wireless device by limiting its ability to communicate with critical internal systems.

There is currently no public evidence of active exploitation or a publicly available proof-of-concept for the disclosed vulnerabilities. However, the unauthenticated nature and critical severity of the internal API flaws make rapid patching essential for WatchGuard AP deployments.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link