Skip to content
Critical Command Injection and Authentication Flaws in WatchGuard Access Points

Critical Command Injection and Authentication Flaws in WatchGuard Access Points

First seen 29 Sep 2026, 08:09 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 08:10 UTC
  • •Three critical vulnerabilities in WatchGuard APs allow command injection and authentication bypass.
  • •Firmware versions prior to 3.4.8 are affected; updates are available to mitigate risks.
  • •No confirmed exploitation of the vulnerabilities has been reported as of now.

Three critical vulnerabilities have been identified in WatchGuard's access points, allowing attackers to execute arbitrary commands and bypass authentication. The flaws include CVE-2026-101891, which permits unauthenticated access to a valid API session, and CVE-2026-86102, enabling command injection through the internal API service. The third vulnerability, CVE-2026-87969, allows authenticated administrators to execute arbitrary commands via crafted input. All three vulnerabilities are classified as critical or high risk, with CVSS scores of 9.3 and 8.6 respectively. WatchGuard has released firmware updates to address these issues, and users are urged to apply them immediately. As of the latest reports, there is no evidence that these vulnerabilities have been exploited in the wild. The affected firmware versions are those prior to 3.4.8. WatchGuard has not disclosed specific detection methods for potential attacks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-28
CVE-2026-86102 published
An OS command injection vulnerability allows network access to execute arbitrary commands.
psirt.watchguard.com
2026-09-28
CVE-2026-87969 published
An OS command injection vulnerability in the diagnostic CLI allows arbitrary command execution by authenticated users.
psirt.watchguard.com
2026-09-28
CVE-2026-101891 published
An improper access control vulnerability allows unauthenticated attackers to obtain a valid API session.
psirt.watchguard.com
2026-09-29
Firmware update released
WatchGuard released firmware 3.4.8 and newer to address the identified vulnerabilities.
Heise.De

More articles in this cluster (4)

Following this threat?

Track WatchGuard and CVE-2026-101891 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed