Decoding the world of cybersecurity

WatchGuard patches critical access-point flaws

WatchGuard has fixed two critical wireless access-point vulnerabilities that can provide unauthenticated API access or operating-system command execution.

WatchGuard patches critical access-point flaws
Summary
  • CVE-2026-101891 allows an unauthenticated attacker with network access to obtain a valid internal API session.
  • CVE-2026-86102 can allow command execution through an internal management API; both are rated 9.3 under CVSS 4.0.
  • WatchGuard AP versions before 3.4.8 are affected.

WatchGuard has released fixes for two critical vulnerabilities affecting its wireless access points, including weaknesses that can provide unauthenticated access to an internal API or allow operating-system command execution.

The vulnerabilities affect WatchGuard AP releases from version 1.0 up to, but not including, 3.4.8. Version 3.4.8 is listed as unaffected.

CVE-2026-101891 is an improper access-control vulnerability in an API service. WatchGuard says an unauthenticated attacker with network access to an affected access point can obtain a valid internal API session.

The flaw carries a CVSS 4.0 score of 9.3.

A second vulnerability, CVE-2026-86102, also has a 9.3 score and affects the internal management API. WatchGuard says the command-injection weakness can allow execution of commands on the underlying operating system.

The company also disclosed CVE-2026-87969, an authenticated command-injection vulnerability in the diagnostic command-line interface rated 8.6.

The affected devices are wireless access points rather than ordinary endpoints, which changes how organisations are likely to find and remediate them. Access points can be spread across offices, branches, warehouses, schools, retail premises, manufacturing sites, and outdoor locations.

They may also fall outside vulnerability-management processes centred on servers and employee devices, particularly where networking hardware is maintained by a separate infrastructure team, managed service provider, or local administrator.

The first flaw requires network access to the affected access point rather than being described as universally reachable from the public internet. That limits some scenarios but still creates risk inside shared, guest, branch, or already partially compromised network environments.

The presence of authentication weakness alongside command injection is sensitive because management APIs sit behind the trust boundary intended to prevent unauthorised configuration and operating-system access.

WatchGuard’s advisory does not present the flaws as part of a confirmed active exploitation campaign. They should therefore be distinguished from the emergency edge-device vulnerabilities that have recently produced live incident response across enterprise networks.

The immediate issue is asset visibility. Organisations need to know whether affected WatchGuard access points are deployed and whether they have actually received version 3.4.8.

Wireless infrastructure can remain in service for years, and upgrades may be delayed because network teams are cautious about disrupting connectivity. That can leave a long patch tail in equipment occupying a valuable position inside the network.

The vulnerabilities are therefore best treated as an infrastructure-management problem rather than evidence of current compromise. Their severity comes from the access they can provide where vulnerable devices remain reachable, not from a presently confirmed exploitation campaign.

×