Critical WatchGuard Endpoint Security Flaw Exposes Kernel and Process Memory
CVE-2026-13043 lets local users bypass WatchGuard's PSKMAD driver checks and read kernel and process memory.
CVE-2026-13043, rated CVSS 9.3, is a flaw in the Panda Kernel Memory Access Driver pskmad.sys used by Panda Security and WatchGuard endpoint products. Researcher Juan Sacco showed a local authenticated attacker can bypass the PsOpenPacket000 handshake on PSMEMDriver and use IOCTLs to transfer memory, map process memory, and read IA32_LSTAR, which can weaken KASLR. A proof of concept dumped LSASS on Windows 11 25H2 with VBS, HVCI, and kCET enabled; the report characterizes this as information disclosure, not verified code execution. Panda said it resolved the issue in October 2026, but affected versions and fixed releases were not confirmed because the vendor advisory could not be retrieved.