Critical WatchGuard API Vulnerabilities Enables Command Execution Attacks
WatchGuard patched three AP vulnerabilities, including two unauthenticated critical flaws with CVSS 9.3, in firmware version 3.4.8.
WatchGuard disclosed three vulnerabilities affecting WatchGuard AP devices running firmware 1.0 through 3.4.7, all fixed in version 3.4.8. CVE-2026-86102 (CVSS v4 9.3) is an unauthenticated OS command injection in the internal management API, and CVE-2026-101891 (9.3) is an improper access control flaw in the same API allowing unauthenticated access to protected functionality. CVE-2026-87969 (8.6) is a command injection via the diagnostic CLI requiring administrator privileges. No active exploitation or public proof-of-concept has been observed.
- CVE-2026-86102: unauthenticated OS command injection in WatchGuard AP internal management API, CVSS v4 9.3
- CVE-2026-101891: improper access control in internal API, CVSS 9.3, unauthenticated
- CVE-2026-87969: authenticated command injection via diagnostic CLI, CVSS 8.6
- All fixed in AP firmware 3.4.8; devices before that version should be upgraded immediately
- No evidence of active exploitation or public PoC yet
Vulnerabilities mentionedAll →
- CVE-2026-1018919.3—Unauthenticated API session flaw in WatchGuard access pointspublished · WatchGuard Access Points
- CVE-2026-861029.3—OS command injection in WatchGuard AP internal APIpublished · WatchGuard AP (internal API service)+1 related
| CVE | Vulnerability |
|---|
Full article519 words · extracted from cybersecuritynews.com · click to collapse
WatchGuard has disclosed three security vulnerabilities affecting WatchGuard AP devices, including two critical flaws that could allow attackers to gain unauthenticated access and execute commands on vulnerable access points.
Organizations using WatchGuard AP firmware earlier than version 3.4.8 should apply the available update immediately. The vulnerabilities were published on September 28, 2026, and affect WatchGuard AP versions from 1.0 through 3.4.7.
WatchGuard addressed all three issues in version 3.4.8. The most serious issue, tracked as CVE-2026-86102, carries a CVSS v4 score of 9.3. The vulnerability is an OS command injection flaw in the internal management API service.
An attacker with network access to a vulnerable WatchGuard AP could send crafted input to trigger arbitrary shell command execution on the underlying operating system.
No authentication or user interaction is required, making the bug especially dangerous where the affected API service is reachable from untrusted networks.
WatchGuard API Vulnerabilities
A second critical vulnerability, CVE-2026-101891, is also rated 9.3. It stems from improper access control in an internal API service on WatchGuard access points. The flaw allows an unauthenticated attacker with network access to access functionality that should be protected.
This issue could provide a path for attackers to interact with internal management capabilities and potentially support follow-on compromise attempts against the device or connected environment.
The third vulnerability, CVE-2026-87969, is a high-severity command injection issue with a CVSS v4 score of 8.6. Unlike the two critical flaws, exploitation requires authenticated administrator privileges.
A malicious or compromised administrator account could supply crafted input through the diagnostic command-line interface and execute arbitrary operating system commands on the WatchGuard AP.
Command injection vulnerabilities are particularly serious in network appliances because compromised access points can become a foothold inside enterprise networks.
Attackers may use command execution to collect configuration data, modify device settings, deploy persistence mechanisms, intercept network traffic, or attempt lateral movement toward other systems.
Devices exposed through management networks, remote-access paths, or poorly segmented wireless infrastructure may face greater risk.
Security teams should first identify all deployed WatchGuard AP devices and verify their firmware versions. Prioritize upgrading devices running a release earlier than 3.4.8.
Administrators should also restrict access to AP management interfaces and internal API services. They should be reachable only from trusted administrative networks.
Organizations should review access logs, administrative activity, diagnostic CLI usage, and configuration changes for signs of unexpected activity. They should also rotate administrative credentials if there is any indication that an AP management account may have been exposed.
Network segmentation can reduce the impact of a compromised wireless device by limiting its ability to communicate with critical internal systems.
There is currently no public evidence of active exploitation or a publicly available proof-of-concept for the disclosed vulnerabilities. However, the unauthenticated nature and critical severity of the internal API flaws make rapid patching essential for WatchGuard AP deployments.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.