Junglewise Threat Intelligence

CVE-2026-41286: WatchGuard Agent stack overflow in discovery service

CVE-2026-41286 · Severity: medium · CVSS 6.5 · Published 2026-05-06

Technologies: Watchguard Agent. Vendors: Watchguard.

Executive brief

The WatchGuard Agent, a software component used for managing and monitoring Windows devices, contains a security flaw in its discovery service. An attacker on the same local network can exploit this to crash the agent service, leading to a denial-of-service condition. This prevents the agent from performing its management tasks and may disrupt security operations on the affected machine.

Technical details

A stack-based buffer overflow (CWE-121) exists in the WatchGuard Agent discovery service on Windows. The vulnerability is triggered when the service processes specially crafted discovery packets, leading to a memory corruption that crashes the process. An unauthenticated attacker located on the same adjacent network (Layer 2) can exploit this without user interaction. The primary impact is a denial-of-service (DoS) of the agent service. The issue is resolved in WatchGuard Agent version 1.25.03.0000.

Affected products

  • WatchGuard Agent (Windows) up to and including 1.25.02.0000

Timeline

  • 2026-05-06: disclosed
  • 2026-05-06: advisory
  • 2026-05-06: patched: Fixed in version 1.25.03.0000

References

Related threats