Critical WatchGuard Endpoint Security Flaw Exposes Kernel and Process Memory
CVE-2026-13043 lets local users bypass WatchGuard's PSKMAD driver checks and read kernel and process memory.
CVE-2026-13043, rated CVSS 9.3, is a flaw in the Panda Kernel Memory Access Driver pskmad.sys used by Panda Security and WatchGuard endpoint products. Researcher Juan Sacco showed a local authenticated attacker can bypass the PsOpenPacket000 handshake on PSMEMDriver and use IOCTLs to transfer memory, map process memory, and read IA32_LSTAR, which can weaken KASLR. A proof of concept dumped LSASS on Windows 11 25H2 with VBS, HVCI, and kCET enabled; the report characterizes this as information disclosure, not verified code execution. Panda said it resolved the issue in October 2026, but affected versions and fixed releases were not confirmed because the vendor advisory could not be retrieved.
- CVE-2026-13043 is scored CVSS 9.3 in pskmad.sys.
- A local user can bypass the driver's authentication handshake.
- A PoC dumped LSASS on hardened Windows 11 25H2.
- Demonstrated impact is disclosure, not confirmed code execution.
- Affected versions and fixed releases remain unconfirmed.
Vulnerabilities mentionedAll →
- CVE-2026-130439.3<1%Missing authentication in WatchGuard PSKMAD kernel driverpublished · WatchGuard Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-13043 |
Full article543 words · extracted from gbhackers.com · click to collapse
A critical vulnerability exists in WatchGuard endpoint security products that could allow a local, authenticated attacker to bypass driver authentication and access sensitive kernel and process memory.
This vulnerability is tracked as CVE-2026-13043 and has a reported CVSS score of 9.3. It affects the Panda Kernel Memory Access Driver (pskmad.sys), as noted in an advisory dated October 5, 2026.
WatchGuard Endpoint Security Flaw
Researcher Juan Sacco discovered the vulnerability in the PSKMAD driver used by Panda Security and WatchGuard products. According to the advisory, Panda confirmed and resolved the issue in October 2026.
However, the vendor’s advisory was not retrievable during verification, leaving the affected product versions, fixed releases, and details on remediation unconfirmed.
The vulnerability arises from a lack of authentication in a driver interface that translates user-controlled requests into privileged kernel operations.
The driver exposes the PSMEMDriver device, which allows user-mode applications to request memory access through input/output control commands. Although the opening procedure includes an extended-attribute handshake called PsOpenPacket000, this vulnerability allows an attacker to bypass the intended access-control gate.
The proof of concept for this vulnerability exercises four operations: memory transfer, entry mapping, entry unmapping, and model-specific register access.
All four operations utilize METHOD_BUFFERED and FILE_ANY_ACCESS. These settings define request handling and IOCTL access requirements. However, they do not inherently determine whether every local user can open the device. Device permissions and the authentication failure are crucial for exploitation.
One demonstrated capability involves reading IA32_LSTAR, a processor register associated with the system call entry point. Revealing this privileged address to user mode can expose kernel address information and potentially undermine kernel address space layout randomization.
Additionally, the driver accepts a target process identifier and virtual address; it maps the requested memory, transfers its contents to the caller, and then releases the mapping.

Research indicates the capability to read page-sized chunks across committed, readable process memory regions, resulting in a hexdump of the target process.
It also reports a memory dumping demonstration of the Local Security Authority Subsystem Service (LSASS) on Windows 11 25H2 with virtualization-based security, hypervisor-protected code integrity, and kernel hardware-enforced stack protection enabled. This demonstration does not imply that every configuration or protected process is equally accessible.
Successful exploitation of this vulnerability could disclose credentials, authentication tokens, session data, private keys, browser information, and application secrets stored in memory.
The demonstrated capabilities primarily indicate information disclosure, rather than verified arbitrary code execution. Installing or launching the driver when it is absent is a separate prerequisite and should not be confused with accessing an already installed vulnerable endpoint component.
Administrators should obtain vendor-confirmed fixed releases and prioritize remediation for affected endpoints. Recommended defensive measures include restricting access to the device, enforcing caller authentication and process-access checks, validating request parameters, removing unnecessary register-reading functionality, and monitoring unexpected access to the PSMEMDriver.
Where operationally feasible, organizations can block the vulnerable driver after confirming compatibility and testing endpoint protection.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.