CVE-2026-13079

WatchGuard Mobile VPN with SSL Windows Client Local Privilege Escalation

High 7.3 CVSS v4.0 › Published 2026-07-02Updated 2026-08-27

Summary #

A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the machine where the client is installed.

This issue affects the Mobile VPN with SSL client for Windows up to and including 2026.2.

Product status #

ProductAffectedNot affected
Mobile VPN with SSL Client
Windows >= 12.0, < 2026.2.1>= 2026.2.1

Weakness Type and Impact #

  • CWECWE-732Incorrect Permission Assignment for Critical Resource
  • CAPECCAPEC-17Using Malicious Files

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Mobile VPN with SSL Client 2026.2.1

References #

Credits #

  • Paul Arzelier, Truesecfinder