WatchGuard has identified three serious security flaws in its AP (Access Point) firmware—two rated critical—that could allow attackers to execute commands on vulnerable devices without authentication. These vulnerabilities impact all firmware versions before 3.4.8, i.e. versions from 1.0 through 3.4.7; a patched release (3.4.8) is now available.
What the Vulnerabilities Involve
The most severe issue, CVE-2026-86102 (CVSS v4 score 9.3), is an OS command injection in WatchGuard’s internal management API. An attacker with network reach to a vulnerable AP can send specially crafted input and gain arbitrary shell execution. No login or user interaction is needed, making this especially dangerous if the API is exposed to untrusted networks.
The second critical flaw, tracked as CVE-2026-101891, is likewise rated 9.3. This stems from improper access control in an internal API. It allows an unauthenticated attacker to invoke functions that should be behind security barriers, potentially facilitating further compromise of the device or adjacent network infrastructure.
The third bug, CVE-2026-87969 (CVSS 8.6), requires administrator credentials. It’s a command-injection vulnerability via the diagnostic CLI interface. An attacker who has admin access could inject commands through the CLI, with full privilege over the operating system on the AP.
Risks, Remediation & Mitigation
Exploiting the first two flaws requires only network access to vulnerable WatchGuard APs; the third requires an authenticated admin user. The risks range from altering configurations, installing persistence mechanisms, intercepting traffic, or even moving laterally within a compromised environment. Devices exposed through poorly segmented networks, remote paths, or wireless infrastructure are especially vulnerable.
To address the threat, WatchGuard users should immediately update any APs running firmware older than version 3.4.8. Administrators should also constrain management interfaces and internal API endpoints so they are accessible only from secure, trusted administrative networks.
Additional steps include reviewing logs for unusual administrative or diagnostic activity, rotating credentials if any exposure is suspected, and implementing network segmentation to limit the damage if a wireless device is breached.
So far, there have been no confirmed public exploitations or proof-of-concepts published for any of the three vulnerabilities. However, the severity and the lack of required authentication for two of them amplify the urgency of deploying the patches.