WatchGuard security advisory (AV26-990)
WatchGuard Endpoint Security kernel driver flaw CVE-2026-13043 allows arbitrary kernel memory access.
Canadian Cyber Centre advisory AV26-990, dated October 2, 2026, says WatchGuard Endpoint Security before 8.00.26.0012 is vulnerable as of October 1, 2026. CVE-2026-13043 is missing authentication in a kernel memory-access driver and allows arbitrary kernel memory access. The centre tells users and administrators to review WatchGuard's advisories and apply updates. The notice does not report exploitation in the wild.
- CVE-2026-13043 affects Endpoint Security before 8.00.26.0012.
- Missing authentication in a kernel memory-access driver allows arbitrary kernel memory access.
- Canadian Cyber Centre advisory AV26-990 urges administrators to update.
- No in-the-wild exploitation is reported.
Vulnerabilities mentionedAll →
- CVE-2026-130439.3<1%Missing authentication in WatchGuard PSKMAD kernel driverpublished · WatchGuard Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-13043 |
Full article69 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-990
Date: October 2, 2026
As of October 1, 2026, WatchGuard is affected by a vulnerability in the following product:
- Endpoint Security
- Prior to 8.00.26.0012
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/watchguard-security-advisory-av26-990