Critical WatchGuard AP Flaws Let Unauthenticated Attackers Execute Arbitrary Commands
WatchGuard patched two unauthenticated critical AP flaws enabling remote command execution and API access.
WatchGuard disclosed three access-point vulnerabilities affecting firmware 1.0 through 3.4.7 and fixed them in version 3.4.8, published September 28, 2026. CVE-2026-86102 (CVSS 9.3) is unauthenticated OS command injection in an internal management API, and CVE-2026-101891 (CVSS 9.3) lets a remote unauthenticated attacker obtain a valid API session. CVE-2026-87969 (CVSS 8.6) is command injection in the diagnostic CLI that requires administrator credentials. The vendor reported no confirmed in-the-wild exploitation or public proof of concept.