AI analysis
CVE-2026-13043 is a missing-authentication flaw (CWE-306), also associated with hard-coded credentials (CWE-798), in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products. A local attacker who is already authenticated on the host can bypass the driver’s access-control handshake and issue arbitrary privileged commands to the driver. The published impact is disclosure of kernel and process memory; the CVSS 4.0 score of 9.3 also rates confidentiality, integrity, and availability as high for the vulnerable system and subsequent systems. Affected version ranges were not included in the provided data, so deployments of WatchGuard endpoint products that load PSKMAD should be checked against the vendor advisory. No public proof of concept is known and the CVE is not in CISA KEV, so exploitation is not known to be occurring in the wild.
What to do: Check WatchGuard’s advisory for this CVE and install the patched endpoint-agent and PSKMAD driver builds as soon as they are published; no fixed version range was included in the data provided here. Until then, restrict local logon on hosts running these products and review endpoint logs for unexpected use of the kernel memory-access driver. Network-only controls do not address this issue, because the attacker must already be authenticated locally.
Affected
| WatchGuard Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products | — |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process memory.