WatchGuard TechnologiesCVE-2026-87969
WatchGuard AP: command injection
High8.6CVE-2026-87969 · Published Sep 28, 2026
An OS command injection vulnerability in the WatchGuard AP diagnostic CLI allows an authenticated administrator to execute arbitrary operating system commands by supplying crafted input.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| WatchGuard AP Product | >= 1.0, < 3.4.8 | 3.4.8 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More WatchGuard Technologies advisories
All WatchGuard Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 30 | WatchGuard Technologies Fireware OS: integer overflow | High8.2 | 2026.3.2+3 more |
| Sep 30 | WatchGuard Technologies Fireware OS: resource exhaustion | High7.1 | 2026.3.2+3 more |
| Sep 30 | WatchGuard Technologies Fireware OS: path traversal | High8.2 | 12.5.21+3 more |
| Sep 30 | WatchGuard Technologies Fireware OS: unsafe deserialization | High7.5 | 2026.3.2+3 more |
| Sep 28 | WatchGuard AP: command injection | Critical9.3 | 3.4.8 |
| Sep 28 | WatchGuard AP: improper access control | Critical9.3 | 3.4.8 |