WatchGuard security advisory (AV26-972)
Canadian Cyber Centre relayed three WatchGuard AP vulnerabilities, including unauthenticated API access and command injection, fixed before version 3.4.8.
The Canadian Centre for Cyber Security issued advisory AV26-972 on September 29, 2026, covering three WatchGuard AP vulnerabilities affecting versions prior to 3.4.8. CVE-2026-101891 is improper access control in the API service allowing unauthenticated access, CVE-2026-86102 is command injection in the internal management API allowing command execution, and CVE-2026-87969 is authenticated command injection in the diagnostic CLI. Users and administrators are encouraged to review WatchGuard advisories and apply updates as they become available.
- Three CVEs affect WatchGuard AP devices before firmware 3.4.8.
- CVE-2026-86102 allows command execution via internal management API command injection.
- CVE-2026-101891 permits unauthenticated API access.
- Canadian Cyber Centre urges applying updates as they become available.
Vulnerabilities mentionedAll →
- CVE-2026-1018919.3—Unauthenticated API session flaw in WatchGuard access pointspublished · WatchGuard Access Points
- CVE-2026-861029.3—OS command injection in WatchGuard AP internal APIpublished · WatchGuard AP (internal API service)+1 related
| CVE | Vulnerability |
|---|
Full article87 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-972
Date: September 29, 2026
As of September 28, 2026, WatchGuard is affected by vulnerabilities in the following product:
- WatchGuard AP
- Prior to 3.4.8
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- CVE-2026-101891 — WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access
- CVE-2026-86102 — WatchGuard AP Command Injection in Internal Management API Allows Command Execution
- CVE-2026-87969 — WatchGuard AP Authenticated Command Injection in Diagnostic CLI
- WatchGuard Security Advisories
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/watchguard-security-advisory-av26-972