Junglewise Threat Intelligence

CVE-2026-41287: WatchGuard Agent stack overflow in discovery service

CVE-2026-41287 · Severity: medium · CVSS 6.5 · Published 2026-05-06

Technologies: Watchguard Agent. Vendors: Watchguard.

Executive brief

A security vulnerability exists in the WatchGuard Agent for Windows, a tool used for managing and monitoring devices. An attacker on the same local network can exploit this flaw to crash the agent service, causing it to stop functioning. This results in a denial-of-service condition that prevents the agent from performing its management and discovery tasks.

Technical details

A stack-based buffer overflow (CWE-121) exists within the discovery service component of the WatchGuard Agent for Windows. The vulnerability is triggered when the service processes specially crafted network traffic, leading to a memory corruption event. An unauthenticated attacker located on the same adjacent network (Layer 2) can exploit this to cause a denial-of-service (DoS) by crashing the agent service. The issue affects versions up to and including 1.25.02.0000 and is resolved in version 1.25.03.0000.

Affected products

  • WatchGuard WatchGuard Agent up to and including 1.25.02.0000

Timeline

  • 2026-05-06: disclosed
  • 2026-05-06: advisory
  • 2026-05-06: patched: Fixed in version 1.25.03.0000

References

Related threats