Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-86102: WatchGuard AP lets network attacker run commands
CVE-2026-86102 · published 4 days ago
Summary
The internal management interface of WatchGuard AP can be tricked into running any operating‑system command if an attacker can reach the device on the network. This could let the attacker take control of the AP or use it to attack other systems. Protect it by restricting network access to the management API and applying the latest firmware updates from WatchGuard.
What to do
- Update watchguard watchguard ap to version 3.4.8 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| watchguard | watchguard ap | < 3.4.8 |
Original advisory text
WatchGuard AP Command Injection in Internal Management API Allows Command Execution
An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.
References
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-78OS Command Injection
CWE-863Incorrect Authorization
Timeline
Published28 Sep 2026
Updated30 Sep 2026
First seen28 Sep 2026
Track software like this
Free during beta