logo

Critical WatchGuard Agent Flaws Let Remote Attackers Execute Arbitrary Code

ID: e11668af-e803-50b1-bbea-279616863b0e

STIX ID: report--e11668af-e803-50b1-bbea-279616863b0e

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Tamilselvan

...
...

WatchGuard disclosed two critical vulnerabilities in WatchGuard Agent (CVE-2026-57910 and CVE-2026-57909) affecting versions earlier than 1.25.13.0000 that allow unauthenticated attackers to achieve arbitrary code execution with elevated privileges (root/SYSTEM) via the agent's UDP discovery/command service and a path traversal flaw; both carry CVSS v4.0 scores above 9 and are fixed in 1.25.13.0000 (and related builds). Organizations should immediately identify and upgrade affected agents, restrict unnecessary UDP exposure, monitor TaskExecute activity, and investigate unexpected privileged processes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.