WatchGuard has released details about three security vulnerabilities affecting its AP devices, with two posing critical risks. These flaws could enable unauthorized access and command execution on susceptible access points.
Organizations using firmware versions prior to 3.4.8 are urged to immediately upgrade. The vulnerabilities, disclosed on September 28, 2026, impact WatchGuard APs from versions 1.0 through 3.4.7.
Critical Vulnerabilities in WatchGuard APs
The most severe vulnerability, identified as CVE-2026-86102, is an OS command injection flaw in the internal management API, scoring 9.3 on the CVSS v4 scale. Attackers with network access can exploit this by sending crafted inputs to execute arbitrary shell commands.
No user authentication is required, making this flaw dangerous when the API service is exposed to untrusted networks.
Access Control Flaws and Risk Mitigation
The second critical issue, CVE-2026-101891, also rated 9.3, arises from poor access control in an internal API service. This allows unauthenticated attackers to access protected functionalities, potentially leading to further compromises.
The third vulnerability, CVE-2026-87969, is a high-severity command injection problem, rated 8.6. Exploitation requires authenticated administrator privileges, allowing malicious users to execute operating system commands via the diagnostic command-line interface.
Securing Your Network Against Exploits
Security teams should identify and update all WatchGuard AP devices running firmware versions earlier than 3.4.8. Access to management interfaces and internal API services should be restricted to trusted networks.
Reviewing access logs, administrative activities, and configuration changes is crucial for detecting suspicious actions. Rotating administrative credentials is advised if any exposure is suspected.
Network segmentation can limit the impact of compromised devices by restricting their communication with critical systems. Currently, there is no evidence of active exploitation or public proof-of-concept for these vulnerabilities, but their critical nature necessitates immediate action.
