AI analysis
CVE-2026-86102 is a critical OS command injection flaw (CWE-78), also associated with incorrect authorization (CWE-863), in the internal API service on WatchGuard access points. An attacker who can reach the AP over the network can send a request that the service passes into the underlying operating system as a shell command, without needing privileges or user interaction (CVSS 4.0 9.3, AV:N/AC:L/PR:N/UI:N, high impact to confidentiality, integrity, and availability on the device). Successful exploitation gives arbitrary command execution on the AP operating system, which can fully compromise the access point. Affected version ranges were not stated in the supplied data, so every WatchGuard AP still running a vulnerable internal API build should be treated as in scope until the vendor confirms otherwise. It is not listed in CISA KEV and no public proof-of-concept is known.
What to do: Treat this as critical: restrict network access to WatchGuard AP management and internal API interfaces to trusted management hosts only, and apply the vendor firmware update as soon as WatchGuard publishes a fixed release for your model. Until patched, segment AP management traffic from user and guest networks and review AP logs for unexpected shell or API activity. Do not expose AP management services to the internet.
Affected
| WatchGuard AP (internal API service) | — |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.