CVE-2026-57910

WatchGuard Agent improper authentication allows unauthenticated remote code execution

Critical 9.3 CVSS v4.0 › Published 2026-08-25Updated 2026-09-09

Summary #

Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.

Product status #

ProductAffectedNot affected
WatchGuard Agent
Linux >= 0, < 1.17.01.0000>= 1.17.01.0000
macOS >= 0, < 1.17.21.0000>= 1.17.21.0000
Windows >= 0, < 1.25.13.0000>= 1.25.13.0000

Weakness Type and Impact #

  • CWECWE-306Missing Authentication for Critical Function
  • CWECWE-347Improper Verification of Cryptographic Signature
  • CWECWE-494Download of Code Without Integrity Check
  • CAPECCAPEC-115Authentication Bypass
  • CAPECCAPEC-242Code Injection

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

WatchGuard Agent 1.17.02.0000, WatchGuard Agent 1.17.21.0000, WatchGuard Agent 1.25.13.0000

References #