Critical WatchGuard API Flaws Let Attackers Execute Commands
Key Takeaways WatchGuard has disclosed three security vulnerabilities, including two critical unauthenticated remote command execution flaws, affecting its AP devices. The vulnerabilities impact...
Key Takeaways
- WatchGuard has disclosed three security vulnerabilities, including two critical unauthenticated remote command execution flaws, affecting its AP devices.
- The vulnerabilities impact WatchGuard AP firmware versions 1.0 through 3.4.7.
- The most severe flaws, CVE-2026-86102 and CVE-2026-101891, both carry a CVSS v4 score of 9.3 and allow unauthenticated command execution or access to protected functionality.
- A patch is available in firmware version 3.4.8, and immediate application is strongly recommended.
WatchGuard AP Devices Exposed by Critical API Flaws
WatchGuard has issued an urgent advisory detailing three security vulnerabilities impacting its Access Point (AP) devices. Among these are two critical flaws that could grant attackers unauthenticated access and enable arbitrary command execution on vulnerable wireless access points.
Table Of Content
Organizations currently utilizing WatchGuard AP firmware versions predating 3.4.8 are advised to deploy the latest update immediately. These vulnerabilities, publicly disclosed on September 28, 2026, affect all WatchGuard AP versions from 1.0 up to and including 3.4.7.
WatchGuard addressed all three issues with the release of firmware version 3.4.8. The most severe of the disclosed flaws, identified as CVE-2026-86102, has been assigned a CVSS v4 score of 9.3. This vulnerability is an OS command injection flaw residing within the internal management API service of the affected devices.
An attacker capable of reaching a vulnerable WatchGuard AP over the network could exploit this weakness by sending specially crafted input. This action would trigger the execution of arbitrary shell commands on the underlying operating system. No prior authentication or user interaction is necessary for successful exploitation, significantly elevating the risk, especially if the affected API service is accessible from untrusted network segments.
Critical Unauthenticated Access and Command Injection
A second critical vulnerability, CVE-2026-101891, also received a CVSS v4 score of 9.3. This flaw stems from improper access control within another internal API service on WatchGuard AP devices. It permits an unauthenticated attacker with network access to invoke functionality that should otherwise be protected.
This improper access control could create a pathway for adversaries to interact with internal management capabilities, potentially facilitating further compromise attempts against the device itself or the broader network environment it serves.
The third vulnerability, CVE-2026-87969, is a high-severity command injection issue with a CVSS v4 score of 8.6. Unlike the two critical flaws, exploiting this vulnerability requires authenticated administrator privileges.
In this scenario, a malicious actor or a compromised administrator account could provide specially crafted input via the diagnostic command-line interface. This action would lead to the execution of arbitrary operating system commands on the WatchGuard AP device.
Command injection vulnerabilities in network appliances are particularly concerning because a compromised access point can serve as a critical entry point into an enterprise network. Attackers leveraging such capabilities might collect sensitive configuration data, alter device settings, establish persistent access, intercept network traffic, or attempt to move laterally to other systems within the network. Devices exposed through management networks, remote access pathways, or inadequately segmented wireless infrastructure face heightened risk.
What You Should Do
- Immediately Update Firmware: Identify all deployed WatchGuard AP devices and upgrade any running a version earlier than 3.4.8 to the latest available firmware.
- Restrict Management Access: Limit network access to AP management interfaces and internal API services. These should only be reachable from trusted administrative network segments.
- Monitor for Suspicious Activity: Regularly review access logs, administrative activity, diagnostic CLI usage, and configuration changes for any signs of unexpected or unauthorized actions.
- Rotate Credentials: If there is any indication that an AP management account may have been compromised, rotate all administrative credentials immediately.
- Implement Network Segmentation: Employ robust network segmentation to reduce the potential impact of a compromised wireless device, thereby limiting its ability to communicate with critical internal systems.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.