WatchGuard has disclosed two critical vulnerabilities in its Windows-based WatchGuard Agent that could allow unauthenticated attackers to execute arbitrary code on vulnerable endpoints.
The flaws, tracked as CVE-2026-57910 and CVE-2026-57909, affect WatchGuard Agent versions earlier than 1.25.13.0000 and carry CVSS v4.0 scores of 9.3 and 9.4, respectively.
Both vulnerabilities were published on August 25, 2026. Although WatchGuard said it is not aware of exploitation in the wild, the issues create a serious exposure for organizations operating unpatched endpoint protection deployments.
Critical WatchGuard Agent Flaws
CVE-2026-57910 is an improper authentication vulnerability that enables an unauthenticated attacker with network access to force the WatchGuard Agent to execute attacker-controlled code with elevated privileges.
According to WatchGuard, the attack abuses the agent’s UDP discovery and command service. An attacker can exploit the vulnerable TaskExecute event handler to instruct the agent to download and execute a malicious program.
Because the agent often runs with elevated privileges, successful exploitation could grant root-level access on Linux systems or SYSTEM-level access on Windows endpoints.
The vulnerability is classified under CWE-306, Missing Authentication for Critical Function. WatchGuard also associates it with CWE-347, Improper Verification of Cryptographic Signature, and CWE-494, Download of Code Without Integrity Check.
This combination indicates that the service could accept unauthenticated commands and execute downloaded payloads without sufficiently validating their authenticity or integrity.
Such a weakness could allow attackers to transform a management or security component into a privileged code-execution mechanism.
The second flaw, CVE-2026-57909, is a path traversal vulnerability affecting the same WatchGuard Agent product line. It allows an unauthenticated attacker located on an adjacent network to execute arbitrary code on an affected device.
WatchGuard assigned the flaw a CVSS v4.0 score of 9.4, reflecting the potential for complete compromise of confidentiality, integrity, and availability. The vendor categorized the issue as CWE-94, Improper Control of Generation of Code, alongside CWE-306, Missing Authentication.
Unlike CVE-2026-57910, which is reachable over the network, CVE-2026-57909 requires an attacker to be on an adjacent network.
That requirement may reduce internet-scale exposure, but it remains highly dangerous in environments where attackers can access local network segments through compromised devices, rogue access points, VPN connections, or lateral movement.
Mitigation
Organizations should identify all systems running WatchGuard Agent and upgrade without delay. WatchGuard has addressed CVE-2026-57910 in versions 1.17.02.0000, 1.17.21.0000, and 1.25.13.0000. CVE-2026-57909 is fixed in WatchGuard Agent version 1.25.13.0000.
Security teams should also restrict unnecessary UDP exposure, monitor for suspicious TaskExecute activity, review agent download behavior, and investigate unexpected processes launched with SYSTEM or root privileges.
Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN
