securityonline.info 29 Sept 2026, 01:50 UTC

WatchGuard Access Points Expose Networks to Critical Command Injection

WatchGuard Access Points Expose Networks to Critical Command Injection
CyberSIXT Evidence Panel Source marked as original reporting

ON 29 September 2026, WatchGuard disclosed three vulnerabilities in its access-point firmware, affecting versions from 1.0 up to, but not including, 3.4.8. The flaws comprise two critical issues, each rated 9.3 under CVSSv4, and one high-severity issue rated 8.6. They are tracked as CVE-2026-101891, CVE-2026-86102 and CVE-2026-87969. WatchGuard fixed all three in firmware version 3.4.8.

The reported attack chain begins with CVE-2026-101891, an improper-access-control flaw in an internal API that can allow an unauthenticated attacker on the same network to obtain a valid API session. CVE-2026-86102 can then allow command injection through that API, resulting in arbitrary shell-command execution on the access point because special elements are not properly sanitised.

Separately, CVE-2026-87969 permits an authenticated administrator to trigger similar command injection through the diagnostic command-line interface. The article says neither WatchGuard nor researchers have confirmed exploitation in the wild, and that no public proof-of-concept code has been published. Administrators should update affected access points to version 3.4.8.

View full article

Article by CyberSIXT