Tuesday, September 8, 2026

Critical WatchGuard Agent Flaws Let Unauthenticated Attackers Execute Remote Code

WatchGuard has revealed two critical vulnerabilities in its Windows WatchGuard Agent, which could allow unauthenticated attackers to execute arbitrary code on affected endpoints. These vulnerabilities, tracked as CVE-2026-57910 and CVE-2026-57909, have CVSS v4.0 scores of 9.3 and 9.4, respectively.

Both issues impact WatchGuard Agent versions earlier than 1.25.13.0000. If exploited, these vulnerabilities could give an attacker complete control over the compromised host, potentially granting SYSTEM-level privileges on Windows systems.

Authentication Bypass Enables Code Execution

CVE-2026-57910 is an improper authentication vulnerability affecting the WatchGuard Agent’s UDP discovery and command service.

This flaw allows an unauthenticated attacker with network access to trigger the agent’s TaskExecute event handler, causing the service to download and execute an attacker-controlled program.

Since the WatchGuard Agent typically runs with elevated privileges, successful exploitation could result in arbitrary code execution as root or SYSTEM, depending on the platform and deployment.

In practical terms, this means an attacker could install malware, maintain persistence, access sensitive files, alter security configurations, or use the compromised endpoint as a foothold for lateral movement.

WatchGuard has categorized this flaw under several weakness categories:

  • CWE-306: Missing Authentication for Critical Function
  • CWE-347: Improper Verification of Cryptographic Signature
  • CWE-494: Download of Code Without Integrity Check

This vulnerability presents a high-risk scenario: a remotely accessible service accepts commands without sufficient authentication and retrieves and executes code without proper validation of its integrity or origin.

The second vulnerability, CVE-2026-57909, is a path traversal flaw that also allows unauthenticated remote code execution. Unlike CVE-2026-57910, exploitation of this vulnerability requires the attacker to be on an adjacent network, rather than just having general network access.

WatchGuard notes that a successful attack could result in a complete loss of the affected endpoint protection component’s confidentiality, integrity, and availability.

This issue is mapped to CWE-94, which involves improper control of code generation, and to CWE-306, which relates to missing authentication for a critical function.

While the requirement for adjacent network access reduces exposure compared to vulnerabilities that are exposed to the internet, it still poses a significant risk in enterprise environments.

Attackers who gain access to a Wi-Fi network, a VPN segment, a compromised internal system, or a poorly isolated subnet could target unpatched WatchGuard Agent installations.

As of August 25, 2026, WatchGuard has stated that it is not aware of any exploitation of either vulnerability in the wild. However, the absence of public exploitation should not be seen as a reason to delay remediation, especially since both vulnerabilities allow unauthenticated code execution.

Organizations should upgrade their WatchGuard Agent to version 1.25.13.0000 or later. Specific fixes for CVE-2026-57910 include versions 1.17.02.0000 and 1.17.21.0000, while CVE-2026-57909 specifically requires version 1.25.13.0000.

Security teams should review the versions of the deployed Agent, prioritize systems that are exposed or internally reachable, and monitor for unusual UDP discovery traffic, unexpected TaskExecute activity, and suspicious binary downloads or process launches originating from the WatchGuard Agent service.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Claude Mythos Executes End-to-End Intrusion From Initial Access to Full Domain Compromise

Anthropic’s Claude Mythos Preview has demonstrated the ability to...

WhatsApp Testing Guest Calls for People Without a WhatsApp Account

WhatsApp is developing a guest-call feature that would let...

The 12 Best Antivirus (Endpoint Protection) Software for Business, Compared and Priced

Best value overall: Microsoft Defender for Endpoint — if...

The 12 Best Managed Firewall Services, Compared and Priced

Best value overall: Fortinet. Delivered directly and through the...

Related Articles

Recent News