CVE-2026-57909

WatchGuard Agent path traversal allows unauthenticated remote code execution

Critical 9.4 CVSS v4.0 › Published 2026-08-25Updated 2026-08-26

Summary #

A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.

Product status #

ProductAffectedNot affected
WatchGuard Agent
Windows >= 0, < 1.25.13.0000>= 1.25.13.0000

Weakness Type and Impact #

  • CWECWE-94Improper Control of Generation of Code ('Code Injection')
  • CWECWE-306Missing Authentication for Critical Function
  • CAPECCAPEC-115Authentication Bypass

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

WatchGuard Agent 1.25.13.0000

References #

    Credits #

    • R31nfinder