Junglewise Threat Intelligence

CVE-2026-6787: WatchGuard Agent hard-coded cryptographic key in Windows agent

CVE-2026-6787 · Severity: high · CVSS 7.8 · Published 2026-05-06

Technologies: Watchguard Agent (Windows). Vendors: Watchguard.

Executive brief

A security vulnerability in the WatchGuard Agent for Windows could allow a local user to gain full administrative control over a computer. The software, which is used to manage and secure endpoints, contains a flaw that allows an attacker to inject and run unauthorized code. This could lead to a complete system takeover, allowing the attacker to access sensitive data or disable security protections.

Technical details

The WatchGuard Agent for Windows (versions prior to 1.25.03.0000) contains a hard-coded cryptographic key (CWE-321). This vulnerability allows a local attacker with low privileges to bypass security controls and inject code into existing agent processes. When chained with other service vulnerabilities, this can lead to local privilege escalation (LPE) to SYSTEM. The issue is resolved in version 1.25.03.0000. Attackers must have local access to the target machine to exploit this flaw.

Affected products

  • WatchGuard WatchGuard Agent (Windows) before 1.25.03.0000

Timeline

  • 2026-05-06: disclosed: Initial disclosure by WatchGuard
  • 2026-05-06: patched: Fixed in version 1.25.03.0000
  • 2026-05-06: advisory: WatchGuard advisory WGSA-2026-00013 published

References

Related threats