started · updated
WatchGuard discloses critical vulnerabilities in Windows Agent
WatchGuard has disclosed two critical vulnerabilities in its Windows-based WatchGuard Agent that could allow unauthenticated attackers to execute arbitrary code with elevated privileges. The flaws affect versions earlier than 1.25.13.0000.
One vulnerability, CVE-2026-57910, has a CVSS v4.0 score of 9.3. It involves an improper authentication flaw in the agent’s UDP discovery and command service. An attacker with network access could trigger the TaskExecute event handler to download and execute an attacker-controlled program, potentially gaining SYSTEM-level privileges on Windows systems.
The second vulnerability, CVE-2026-57909, carries a CVSS v4.0 score of 9.4. This is a path traversal flaw that allows an unauthenticated attacker on an adjacent network to execute arbitrary code.
WatchGuard stated it is not currently aware of these vulnerabilities being exploited in the wild, but has advised prompt patching due to the high severity and low attack complexity.