Critical Remote Code Execution Vulnerabilities in WatchGuard Agent

Critical Remote Code Execution Vulnerabilities in WatchGuard Agent

First seen 26 Aug 2026, 11:52 UTC Digital.Nhs.Ukwww.watchguard.compsirt.watchguard.comwww.cve.org 74.0

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities, CVE-2026-57909 and CVE-2026-57910, have been identified in WatchGuard Agent, allowing unauthenticated remote code execution. CVE-2026-57909 involves a path traversal vulnerability, while CVE-2026-57910 is due to improper authentication. Both vulnerabilities can be exploited by attackers on adjacent networks to execute arbitrary code with elevated privileges. The impact includes potential complete system compromise, loss of confidentiality, integrity, and availability of affected systems. WatchGuard has issued advisories urging organizations to apply the necessary updates immediately. The vulnerabilities were published on August 25, 2026, and are considered highly critical due to the ease of exploitation. Organizations using WatchGuard Agent are advised to review the advisories and patch their systems as soon as possible.

Key Points: • CVE-2026-57909 and CVE-2026-57910 allow remote code execution on WatchGuard Agent. • Exploitation can lead to full system compromise and significant data loss. • Immediate patching is recommended as vulnerabilities are critical and easily exploitable.

Timeline

2026-08-25
CVE-2026-57909 and CVE-2026-57910 published
WatchGuard disclosed two critical vulnerabilities in WatchGuard Agent allowing remote code execution.
Digital.Nhs.Uk
2026-08-26
Advisories issued by WatchGuard
WatchGuard released security advisories urging immediate patching of affected systems to mitigate risks.
psirt.watchguard.com
2026-08-26
Current status update
Organizations are encouraged to review advisories and apply relevant updates to protect against exploitation.
Digital.Nhs.Uk