Junglewise Threat Intelligence

CVE-2026-57910: WatchGuard Agent improper authentication in RCE

CVE-2026-57910 · Severity: info · CVSS 9.3 · Published 2026-08-25

Technologies: Watchguard Agent. Vendors: Watchguard.

Executive brief

WatchGuard Agent is a client application that protects endpoints by enforcing security policies and monitoring activity. A flaw in the agent's authentication mechanism allows remote attackers on the network to bypass security checks and execute arbitrary code with elevated system privileges, potentially leading to complete device compromise and lateral movement into corporate networks.

Technical details

The vulnerability stems from improper authentication and weak cryptographic signature verification in the WatchGuard Agent, tracked under CWE-306 (Missing Authentication), CWE-347 (Improper Verification of Cryptographic Signature), and CWE-494 (Download of Code Without Integrity Check). An unauthenticated attacker with network access to the agent can exploit this to trigger arbitrary code execution with elevated privileges. The attack requires no user interaction or prior authentication. Patches are available: Windows version 1.25.13.0000 and later, macOS version 1.17.21.0000 and later, and Linux version 1.17.01.0000 and later.

Affected products

  • WatchGuard Agent Windows < 1.25.13.0000, macOS < 1.17.21.0000, Linux < 1.17.01.0000

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Patched versions available: Windows 1.25.13.0000+, macOS 1.17.21.0000+, Linux 1.17.01.0000+

References

Related threats