CVE-2026-13043

WatchGuard Endpoint Security Missing Authentication in Kernel Memory Access Driver Allows Arbitrary Kernel Memory Access

Critical 9.3 CVSS v4.0 › Published 2026-10-01Updated 2026-10-01

Summary #

A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process memory.

Product status #

ProductAffectedNot affected
Endpoint Security
Windows >= 0, < 8.00.26.0012>= 8.00.26.0012

Weakness Type and Impact #

  • CWECWE-306Missing Authentication for Critical Function
  • CWECWE-798Use of Hard-coded Credentials
  • CAPECCAPEC-115Authentication Bypass
  • CAPECCAPEC-194Fake the Source of Data

Solution #

Update to a fixed release per the affected-version ranges above.

References #