WatchGuard has announced the discovery of three high-impact vulnerabilities in its wireless access point platform. Two of these critical issues allow unauthenticated network attackers to gain API access and execute arbitrary operating-system commands.
These vulnerabilities affect WatchGuard AP firmware versions 1.0 through 3.4.7 and were addressed in version 3.4.8, which the vendor released as a remediation update.
The vulnerabilities were published on September 28, 2026, and are tracked as CVE-2026-86102, CVE-2026-101891, and CVE-2026-87969. The first two vulnerabilities carry CVSS v4.0 scores of 9.3 and are rated as Critical, while the third is rated High with a score of 8.6.
The most serious vulnerability, CVE-2026-86102, is an OS command injection flaw in the WatchGuard AP internal management API service.
An attacker who can reach a vulnerable access point over the network can submit specially crafted input that runs arbitrary shell commands on the access point’s underlying operating system. This attack requires no authentication or user interaction.
This makes the issue particularly dangerous for access points whose management services are accessible from untrusted client networks, remote access infrastructure, flat internal networks, or poorly segmented wireless environments.
If successfully exploited, the attacker could gain execution privileges associated with the affected API service. This could enable device manipulation, persistence, reconnaissance, or using the access point as a foothold within the internal network.
CVE-2026-101891 is a critical improper access control issue in a separate internal API service. It allows an unauthenticated attacker with network access to a vulnerable WatchGuard AP to obtain a valid API session. This could lead to unauthorized access to functions that should be restricted to authenticated administrators.
Although the advisory describes these flaws separately, their presence in internal management services raises significant risk for exposed deployments.
An attacker may exploit the authentication flaw to access management functions and potentially take further action against the access point or the connected network environment. The CVSS v4 vector for CVE-2026-101891 indicates network reachability, low attack complexity, no required privileges, and no user interaction.
WatchGuard has also patched CVE-2026-87969, which is an authenticated command injection flaw in the AP’s diagnostic command-line interface. Unlike the two critical API vulnerabilities, this one requires administrator-level access for exploitation.
A malicious administrator or a threat actor using compromised administrative credentials could provide crafted diagnostic input to execute operating system commands on the access point.
Organizations should immediately inventory their WatchGuard AP deployments and upgrade every device running a version earlier than 3.4.8.
Until all devices are patched, administrators should restrict API and management access to trusted administrative hosts, place access point management interfaces in dedicated VLANs, and block exposure from untrusted wireless, guest, and remote access networks.
As of the publication date, there are no confirmed instances of in-the-wild exploitation or public proof-of-concept for these vulnerabilities. However, the unauthenticated and network-accessible nature of the critical vulnerabilities makes rapid remediation essential.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…