WatchGuard TechnologiesCVE-2026-57909
WatchGuard Agent: path traversal
Critical9.4CVE-2026-57909 · Published Aug 25, 2026 · updated Aug 28, 2026
A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| WatchGuard Agent Product | < 1.25.13.0000 | 1.25.13.0000 |
Details and references
More WatchGuard Technologies advisories
All WatchGuard Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 28 | WatchGuard Technologies Fireware OS: out-of-bounds read | High8.7 | 2026.2.2+3 more |
| Aug 28 | WatchGuard Technologies Fireware OS: denial of service | High8.7 | 2026.2.2+3 more |
| Aug 28 | WatchGuard Technologies Fireware OS: type confusion | Critical9.3 | 2026.2.2+3 more |
| Aug 28 | WatchGuard Technologies Fireware OS: integer overflow | High8.7 | 2026.2.2+3 more |
| Aug 28 | WatchGuard Technologies Fireware OS: heap buffer overflow | Medium6.9 | 2026.2.1+3 more |
| Aug 25 | WatchGuard Agent: improper authentication | Critical9.3 | 1.17.01.0000+2 more |