Skip to content

WatchGuard Agent: improper authentication

Critical9.3CVE-2026-57910 · Published Aug 25, 2026 · updated Sep 9, 2026

Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.

Affected versions

PackageAffectedFixed in
WatchGuard Agent
Product
< 1.17.01.00001.17.01.0000
< 1.25.13.00001.25.13.0000
< 1.17.21.00001.17.21.0000
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-306, CWE-347, CWE-494

More WatchGuard Technologies advisories

All WatchGuard Technologies
Advisory
WatchGuard Technologies Fireware OS: out-of-bounds read
High8.7Aug 28
WatchGuard Technologies Fireware OS: denial of service
High8.7Aug 28
WatchGuard Technologies Fireware OS: type confusion
Critical9.3Aug 28
WatchGuard Technologies Fireware OS: integer overflow
High8.7Aug 28
WatchGuard Technologies Fireware OS: heap buffer overflow
Medium6.9Aug 28
WatchGuard Agent: path traversal
Critical9.4Aug 25

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.