Skip to main content

WatchGuard Releases Security Updates for Critical Vulnerabilities in WatchGuard Agent

CVE-2026-57909 and CVE-2026-57910 could allow unauthenticated remote code execution on affected WatchGuard Agent systems

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

CVE-2026-57909 and CVE-2026-57910 could allow unauthenticated remote code execution on affected WatchGuard Agent systems


Affected platforms

The following platforms are known to be affected:

Threat details

Security agents are attractive targets to attackers

Security agents are attractive targets to attackers because they are trusted, widely deployed, and often operate with elevated privileges. Exploitation of these vulnerabilities could enable an attacker to gain control of affected endpoints, evade security monitoring, move laterally within networks, and deploy follow-on activity such as ransomware or data theft.


Introduction

WatchGuard has released two security advisories to address critical vulnerabilities in WatchGuard Agent. Successful exploitation could allow a remote attacker to execute arbitrary code on affected systems, potentially resulting in full system compromise.

Vulnerabilities:

  • CVE-2026-57909 – Path Traversal / Code Injection vulnerability – CVSSv4: 9.4
  • CVE-2026-57910 – Improper Authentication vulnerability – CVSSv4: 9.3

Remediation advice

Affected organisations are encouraged to review the WatchGuard Advisory for CVE-2026-57909 and WatchGuard advisory for CVE-2026-57910 and apply the relevant update as soon as possible.



Last edited: 26 August 2026 12:20 pm