WatchGuard endpoint driver flaw CVE-2026-13043 exposes kernel memory
CVE-2026-13043 in WatchGuard and Panda endpoint drivers can let a local user read kernel and process memory.
Canadian Centre for Cyber Security advisory AV26-990, dated October 2, 2026, says WatchGuard Endpoint Security before 8.00.26.0012 is vulnerable to CVE-2026-13043, missing authentication in a kernel memory-access driver that allows arbitrary kernel memory access. The centre reports no in-the-wild exploitation and tells administrators to review WatchGuard advisories and apply updates. A GBHackers report dated October 6, 2026, rates the same CVE at CVSS 9.3 in pskmad.sys, the Panda Kernel Memory Access Driver used by Panda Security and WatchGuard endpoint products. Researcher Juan Sacco demonstrated that a local authenticated user can bypass the driver's checks and read kernel and process memory; a proof of concept dumped LSASS on Windows 11 25H2 with VBS, HVCI, and kCET enabled, which that report treats as information disclosure rather than confirmed code execution. The sources disagree on remediation: the Canadian notice gives a fixed cutoff of 8.00.26.0012, while GBHackers says Panda reported an October 2026 fix but affected and fixed versions were unconfirmed because the vendor advisory could not be retrieved.
- CVE-2026-13043 affects WatchGuard Endpoint Security before 8.00.26.0012, per Canadian Cyber Centre advisory AV26-990 dated October 2, 2026, with the product vulnerable as of October 1, 2026.
- The Canadian notice describes missing authentication in a kernel memory-access driver that allows arbitrary kernel memory access, and it reports no exploitation in the wild.
- GBHackers, on October 6, 2026, scores CVE-2026-13043 at CVSS 9.3 in the Panda Kernel Memory Access Driver pskmad.sys used by Panda Security and WatchGuard endpoint products.
- Researcher Juan Sacco showed a local authenticated user can bypass the driver's checks and read kernel and process memory.
- A proof of concept dumped LSASS on Windows 11 25H2 with VBS, HVCI, and kCET enabled; GBHackers characterizes the impact as information disclosure, not verified code execution.
- Sources disagree on the fix: Canada names builds before 8.00.26.0012, while GBHackers says Panda reported an October 2026 resolution but affected and fixed versions could not be confirmed.
Coverage timelineoldest first · each row is one article
- · 6d agoWatchGuard security advisory (AV26-990)
Canadian Centre for Cyber Security· 66
WatchGuard Endpoint Security kernel driver flaw CVE-2026-13043 allows arbitrary kernel memory access.
- · 3d agoCritical WatchGuard Endpoint Security Flaw Exposes Kernel and Process Memory
GBHackers· 66
CVE-2026-13043 lets local users bypass WatchGuard's PSKMAD driver checks and read kernel and process memory.
Vulnerabilities in this storyAll →
- CVE-2026-130439.3<1%Missing authentication in WatchGuard PSKMAD kernel driverpublished · WatchGuard Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-13043 |