Critical WatchGuard AP Flaws Let Unauthenticated Attackers Execute Arbitrary Commands
WatchGuard patched two unauthenticated critical AP flaws enabling remote command execution and API access.
WatchGuard disclosed three access-point vulnerabilities affecting firmware 1.0 through 3.4.7 and fixed them in version 3.4.8, published September 28, 2026. CVE-2026-86102 (CVSS 9.3) is unauthenticated OS command injection in an internal management API, and CVE-2026-101891 (CVSS 9.3) lets a remote unauthenticated attacker obtain a valid API session. CVE-2026-87969 (CVSS 8.6) is command injection in the diagnostic CLI that requires administrator credentials. The vendor reported no confirmed in-the-wild exploitation or public proof of concept.
- CVE-2026-86102 is unauthenticated OS command injection, scored CVSS 9.3.
- CVE-2026-101891 lets unauthenticated attackers obtain an API session, also CVSS 9.3.
- CVE-2026-87969 is authenticated diagnostic CLI injection scored CVSS 8.6.
- Firmware 1.0 through 3.4.7 is affected; 3.4.8 is the fix.
- No confirmed exploitation or public proof of concept was reported.
Vulnerabilities mentionedAll →
- CVE-2026-1018919.3—Unauthenticated API session flaw in WatchGuard access pointspublished · WatchGuard Access Points
- CVE-2026-861029.3—OS command injection in WatchGuard AP internal APIpublished · WatchGuard AP (internal API service)+1 related
| CVE | Vulnerability |
|---|
Full article520 words · extracted from gbhackers.com · click to collapse
WatchGuard has announced the discovery of three high-impact vulnerabilities in its wireless access point platform. Two of these critical issues allow unauthenticated network attackers to gain API access and execute arbitrary operating-system commands.
These vulnerabilities affect WatchGuard AP firmware versions 1.0 through 3.4.7 and were addressed in version 3.4.8, which the vendor released as a remediation update.
Critical WatchGuard AP Flaws
The vulnerabilities were published on September 28, 2026, and are tracked as CVE-2026-86102, CVE-2026-101891, and CVE-2026-87969. The first two vulnerabilities carry CVSS v4.0 scores of 9.3 and are rated as Critical, while the third is rated High with a score of 8.6.
The most serious vulnerability, CVE-2026-86102, is an OS command injection flaw in the WatchGuard AP internal management API service.
An attacker who can reach a vulnerable access point over the network can submit specially crafted input that runs arbitrary shell commands on the access point’s underlying operating system. This attack requires no authentication or user interaction.
This makes the issue particularly dangerous for access points whose management services are accessible from untrusted client networks, remote access infrastructure, flat internal networks, or poorly segmented wireless environments.
If successfully exploited, the attacker could gain execution privileges associated with the affected API service. This could enable device manipulation, persistence, reconnaissance, or using the access point as a foothold within the internal network.
CVE-2026-101891 is a critical improper access control issue in a separate internal API service. It allows an unauthenticated attacker with network access to a vulnerable WatchGuard AP to obtain a valid API session. This could lead to unauthorized access to functions that should be restricted to authenticated administrators.
Although the advisory describes these flaws separately, their presence in internal management services raises significant risk for exposed deployments.
An attacker may exploit the authentication flaw to access management functions and potentially take further action against the access point or the connected network environment. The CVSS v4 vector for CVE-2026-101891 indicates network reachability, low attack complexity, no required privileges, and no user interaction.
WatchGuard has also patched CVE-2026-87969, which is an authenticated command injection flaw in the AP’s diagnostic command-line interface. Unlike the two critical API vulnerabilities, this one requires administrator-level access for exploitation.
A malicious administrator or a threat actor using compromised administrative credentials could provide crafted diagnostic input to execute operating system commands on the access point.
Organizations should immediately inventory their WatchGuard AP deployments and upgrade every device running a version earlier than 3.4.8.
Until all devices are patched, administrators should restrict API and management access to trusted administrative hosts, place access point management interfaces in dedicated VLANs, and block exposure from untrusted wireless, guest, and remote access networks.
As of the publication date, there are no confirmed instances of in-the-wild exploitation or public proof-of-concept for these vulnerabilities. However, the unauthenticated and network-accessible nature of the critical vulnerabilities makes rapid remediation essential.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.