logo

Critical Vulnerabilities in WatchGuard Agent Enable Remote Code Execution

ID: 15ca8727-5481-5a2c-804e-60ebfef65f81

STIX ID: report--15ca8727-5481-5a2c-804e-60ebfef65f81

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

...
...

Two critical unauthenticated remote code execution vulnerabilities (CVE-2026-57909 and CVE-2026-57910) were disclosed in WatchGuard Agent versions before 1.25.13.0000. The flaws—rooted in improper authentication and path traversal—have CVSS scores of 9.3 and 9.4, grant elevated privileges to attackers, are widely deployed across platforms, and have confirmed exploitation in the wild; WatchGuard advises immediate patching to mitigate risks including ransomware and data theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.