Junglewise Threat Intelligence

CVE-2026-57909: WatchGuard Agent path traversal remote code execution

CVE-2026-57909 · Severity: info · CVSS 9.4 · Published 2026-08-25

Technologies: Watchguard Agent. Vendors: Watchguard.

Executive brief

WatchGuard Agent is a system utility deployed on Windows endpoints to provide administrative monitoring and management capabilities. A path traversal flaw in the Agent allows an attacker on the same network segment to bypass authentication and execute arbitrary code on affected systems without requiring user interaction or credentials, potentially compromising the entire host and any sensitive data it contains.

Technical details

The vulnerability is a path traversal leading to code injection (CWE-94) combined with missing authentication for a critical function (CWE-306). An unauthenticated attacker on an adjacent network (same network segment) can exploit the path traversal to manipulate code generation or execution paths, resulting in arbitrary remote code execution. No user interaction or prior authentication is required; the vulnerability is network-reachable via the local network. WatchGuard released a patch in version 1.25.13.0000, and there are currently no reports of active exploitation in the wild.

Affected products

  • WatchGuard Agent Windows < 1.25.13.0000

Timeline

  • 2026-08-25: disclosed
  • 2026-08-26: patched: WatchGuard Agent 1.25.13.0000 released

References

Related threats