ON 29 September 2026, WatchGuard disclosed three vulnerabilities in its access-point firmware, affecting versions from 1.0 up to, but not including, 3.4.8. The flaws comprise two critical issues, each rated 9.3 under CVSSv4, and one high-severity issue rated 8.6. They are tracked as CVE-2026-101891, CVE-2026-86102 and CVE-2026-87969. WatchGuard fixed all three in firmware version 3.4.8.
The reported attack chain begins with CVE-2026-101891, an improper-access-control flaw in an internal API that can allow an unauthenticated attacker on the same network to obtain a valid API session. CVE-2026-86102 can then allow command injection through that API, resulting in arbitrary shell-command execution on the access point because special elements are not properly sanitised.
Separately, CVE-2026-87969 permits an authenticated administrator to trigger similar command injection through the diagnostic command-line interface. The article says neither WatchGuard nor researchers have confirmed exploitation in the wild, and that no public proof-of-concept code has been published. Administrators should update affected access points to version 3.4.8.