Cyber Security News

Critical WatchGuard AP Flaws Let Unauthenticated Attackers Execute Arbitrary Commands

WatchGuard has announced the discovery of three high-impact vulnerabilities in its wireless access point platform. Two of these critical issues allow unauthenticated network attackers to gain API access and execute arbitrary operating-system commands.

These vulnerabilities affect WatchGuard AP firmware versions 1.0 through 3.4.7 and were addressed in version 3.4.8, which the vendor released as a remediation update.

Critical WatchGuard AP Flaws

The vulnerabilities were published on September 28, 2026, and are tracked as CVE-2026-86102, CVE-2026-101891, and CVE-2026-87969. The first two vulnerabilities carry CVSS v4.0 scores of 9.3 and are rated as Critical, while the third is rated High with a score of 8.6.

The most serious vulnerability, CVE-2026-86102, is an OS command injection flaw in the WatchGuard AP internal management API service.

An attacker who can reach a vulnerable access point over the network can submit specially crafted input that runs arbitrary shell commands on the access point’s underlying operating system. This attack requires no authentication or user interaction.

This makes the issue particularly dangerous for access points whose management services are accessible from untrusted client networks, remote access infrastructure, flat internal networks, or poorly segmented wireless environments.

If successfully exploited, the attacker could gain execution privileges associated with the affected API service. This could enable device manipulation, persistence, reconnaissance, or using the access point as a foothold within the internal network.

CVE-2026-101891 is a critical improper access control issue in a separate internal API service. It allows an unauthenticated attacker with network access to a vulnerable WatchGuard AP to obtain a valid API session. This could lead to unauthorized access to functions that should be restricted to authenticated administrators.

Although the advisory describes these flaws separately, their presence in internal management services raises significant risk for exposed deployments.

An attacker may exploit the authentication flaw to access management functions and potentially take further action against the access point or the connected network environment. The CVSS v4 vector for CVE-2026-101891 indicates network reachability, low attack complexity, no required privileges, and no user interaction.

WatchGuard has also patched CVE-2026-87969, which is an authenticated command injection flaw in the AP’s diagnostic command-line interface. Unlike the two critical API vulnerabilities, this one requires administrator-level access for exploitation.

A malicious administrator or a threat actor using compromised administrative credentials could provide crafted diagnostic input to execute operating system commands on the access point.

Organizations should immediately inventory their WatchGuard AP deployments and upgrade every device running a version earlier than 3.4.8.

Until all devices are patched, administrators should restrict API and management access to trusted administrative hosts, place access point management interfaces in dedicated VLANs, and block exposure from untrusted wireless, guest, and remote access networks.

As of the publication date, there are no confirmed instances of in-the-wild exploitation or public proof-of-concept for these vulnerabilities. However, the unauthenticated and network-accessible nature of the critical vulnerabilities makes rapid remediation essential.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

3 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago