logo

Critical WatchGuard Agent Flaws Let Unauthenticated Attackers Execute Remote Code

ID: 38d6e7cf-4b9c-5281-99a0-90dd393b5c50

STIX ID: report--38d6e7cf-4b9c-5281-99a0-90dd393b5c50

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-08-26

Date Updated: 2026-08-27

Author: Divya

...
...

Two critical unauthenticated remote code execution vulnerabilities in WatchGuard Agent (CVE-2026-57910 and CVE-2026-57909, CVSS 9.3/9.4) allow attackers to trigger TaskExecute or exploit a path traversal to download/execute arbitrary code with elevated (SYSTEM/root) privileges; WatchGuard recommends upgrading to Agent version 1.25.13.0000 or later and monitoring for suspicious UDP discovery, TaskExecute activity, and unexpected binary downloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.