Heise.De Critical Command Injection and Authentication Flaws in WatchGuard Access Points
Article Content
- •Three critical vulnerabilities in WatchGuard APs allow command injection and authentication bypass.
- •Firmware versions prior to 3.4.8 are affected; updates are available to mitigate risks.
- •No confirmed exploitation of the vulnerabilities has been reported as of now.
Three critical vulnerabilities have been identified in WatchGuard's access points, allowing attackers to execute arbitrary commands and bypass authentication. The flaws include CVE-2026-101891, which permits unauthenticated access to a valid API session, and CVE-2026-86102, enabling command injection through the internal API service. The third vulnerability, CVE-2026-87969, allows authenticated administrators to execute arbitrary commands via crafted input. All three vulnerabilities are classified as critical or high risk, with CVSS scores of 9.3 and 8.6 respectively. WatchGuard has released firmware updates to address these issues, and users are urged to apply them immediately. As of the latest reports, there is no evidence that these vulnerabilities have been exploited in the wild. The affected firmware versions are those prior to 3.4.8. WatchGuard has not disclosed specific detection methods for potential attacks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track WatchGuard and CVE-2026-101891 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CISA Adds Seven Exploited Vulnerabilities; IBM Warns of Langflow OSS Flaws CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities Catalog, including CVE-2026-9586, a SQL injection vulnerability in Sangoma Switchvox, and several others affecting SonicWall and JFrog products. These vulnerabilities pose significant risks due to active exploitation. Concurrently, IBM has…
Critical Vulnerabilities in SxDevOps Expose Remote Code Execution Risks On September 20, 2026, multiple critical vulnerabilities were disclosed in SxDevOps versions 1.0 and 1.1, including CVE-2026-93970, CVE-2026-93969, and CVE-2026-93971. These vulnerabilities allow for remote code execution (RCE) and the exploitation of hardcoded credentials, posing significant risks to organizations…