High-Severity WatchGuard Agent Flaws Grant Full SYSTEM Privileges on Windows
ID: ab688996-4135-56bf-bf20-170767217db9
STIX ID: report--ab688996-4135-56bf-bf20-170767217db9
Feed Name: securityonline.info
WatchGuard released a critical security update for its Windows WatchGuard Agent to remediate multiple vulnerabilities — notably two chained flaws (CVE-2026-6787, CVE-2026-6788) enabling local privilege escalation to NT AUTHORITY\SYSTEM, an authenticated local privilege escalation in the patch management component (CVE-2026-41288), and two unauthenticated stack-based buffer overflows in the Discovery Service (CVE-2026-41286, CVE-2026-41287) that can cause DoS; all versions up to 1.25.02.0000 are affected and administrators should deploy 1.25.03.0000 immediately as no practical workarounds exist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
