WatchGuard Agent Vulnerabilities Let Attackers Grant Full SYSTEM Privileges on Windows
ID: edf012bd-0d20-5d5a-ac34-79adf96ee080
STIX ID: report--edf012bd-0d20-5d5a-ac34-79adf96ee080
Feed Name: cybersecurityNews.com
WatchGuard has released urgent security updates for the WatchGuard Agent on Windows to fix four high-severity vulnerabilities: a chained local privilege escalation (CVE-2026-6787/CVE-2026-6788, CVSS 8.5) that can yield NT AUTHORITY\SYSTEM, a permission-misconfiguration elevation (CVE-2026-41288, CVSS 7.3), and two stack-based buffer overflows in the discovery service (CVE-2026-41286/CVE-2026-41287, CVSS 7.1) that allow unauthenticated local-network attackers to cause service crashes and DoS; administrators are advised to update to WatchGuard Agent 1.25.03.0000 immediately since no other mitigations exist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
