logo

WatchGuard Agent Vulnerabilities Let Attackers Grant Full SYSTEM Privileges on Windows

ID: edf012bd-0d20-5d5a-ac34-79adf96ee080

STIX ID: report--edf012bd-0d20-5d5a-ac34-79adf96ee080

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-05-07

Date Updated: 2026-05-14

Author: Abinaya

...
...

WatchGuard has released urgent security updates for the WatchGuard Agent on Windows to fix four high-severity vulnerabilities: a chained local privilege escalation (CVE-2026-6787/CVE-2026-6788, CVSS 8.5) that can yield NT AUTHORITY\SYSTEM, a permission-misconfiguration elevation (CVE-2026-41288, CVSS 7.3), and two stack-based buffer overflows in the discovery service (CVE-2026-41286/CVE-2026-41287, CVSS 7.1) that allow unauthenticated local-network attackers to cause service crashes and DoS; administrators are advised to update to WatchGuard Agent 1.25.03.0000 immediately since no other mitigations exist.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.