WatchGuard TechnologiesCVE-2026-57910
WatchGuard Agent: improper authentication
Critical9.3CVE-2026-57910 · Published Aug 25, 2026 · updated Sep 9, 2026
Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| WatchGuard Agent Product | < 1.17.01.0000 | 1.17.01.0000 |
| < 1.25.13.0000 | 1.25.13.0000 | |
| < 1.17.21.0000 | 1.17.21.0000 |
Details and references
More WatchGuard Technologies advisories
All WatchGuard Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 28 | WatchGuard Technologies Fireware OS: out-of-bounds read | High8.7 | 2026.2.2+3 more |
| Aug 28 | WatchGuard Technologies Fireware OS: denial of service | High8.7 | 2026.2.2+3 more |
| Aug 28 | WatchGuard Technologies Fireware OS: type confusion | Critical9.3 | 2026.2.2+3 more |
| Aug 28 | WatchGuard Technologies Fireware OS: integer overflow | High8.7 | 2026.2.2+3 more |
| Aug 28 | WatchGuard Technologies Fireware OS: heap buffer overflow | Medium6.9 | 2026.2.1+3 more |
| Aug 25 | WatchGuard Agent: path traversal | Critical9.4 | 1.25.13.0000 |