Critical WatchGuard Agent Flaws Enable Unauthenticated Code Execution on Windows Endpoints
WatchGuard has disclosed two critical vulnerabilities in its Windows-based WatchGuard Agent that could allow unauthenticated attackers to execute arbitrary code on vulnerable endpoints.
Tracked as CVE-2026-57910 and CVE-2026-57909, the flaws carry CVSS v4.0 scores of 9.3 and 9.4, making them serious risks for organizations using WatchGuard Endpoint Security. WatchGuard’s latest Windows Agent release, version 1.25.13.000, addresses both vulnerabilities.
The vulnerabilities affect older WatchGuard Agent deployments and were disclosed in August 2026. According to WatchGuard’s release documentation, version 1.25.13.000 was released on August 19 and specifically resolves both CVE-2026-57909 and CVE-2026-57910.
Critical WatchGuard Agent Flaws
The vendor has not indicated that these vulnerabilities are being actively exploited in the wild, but their high severity and potential for privileged code execution make rapid remediation important.
CVE-2026-57910 is an improper authentication vulnerability that could allow an attacker with network access to abuse communications handled by the WatchGuard Agent.
The vulnerability is associated with CWE-306, Missing Authentication for Critical Function, and could allow unauthorized operations to be performed through the agent.
Because the WatchGuard Agent is responsible for communications between managed endpoints and WatchGuard services, compromise of this component could provide an attacker with a powerful execution path on affected systems.
WatchGuard describes the patched release as preventing malicious processes with network access from establishing fraudulent communications and performing unauthorized operations.
The second vulnerability, CVE-2026-57909, is also rated critical, with a CVSS v4.0 score of 9.4. WatchGuard identifies the issue as allowing a malicious process to drop an unauthorized executable file onto the computer.
The vulnerability is associated with improper control over code generation and missing authentication, creating the potential for attackers to abuse the agent to introduce executable content onto affected endpoints.
The security implications are significant because endpoint security agents operate with extensive system privileges and have access to sensitive operating-system functions.
If an attacker successfully turns an exposed agent service into a code-execution mechanism, the resulting compromise could potentially be used to install malware, establish persistence, disable security controls, steal credentials, or conduct further lateral movement.
The exact impact will depend on the endpoint configuration and the privileges available to the compromised agent process.
Although CVE-2026-57909 may require access to a reachable network environment rather than unrestricted internet exposure, this should not be considered a sufficient security boundary.
Attackers frequently obtain network access through compromised endpoints, phishing, malicious wireless infrastructure, exposed remote-access services, or previously established footholds.
Once inside a corporate environment, vulnerable security-management components can become attractive targets for privilege escalation and lateral movement.
Organizations should therefore identify all systems running WatchGuard Agent and prioritize upgrading to version 1.25.13.000 or later.
WatchGuard confirms that the latest Windows Agent resolves both CVE-2026-57909 and CVE-2026-57910. Administrators can review endpoint versions through the WatchGuard Endpoint Security management interface and use available agent upgrade mechanisms where necessary.
Security teams should additionally review network exposure around WatchGuard Agent services, restrict unnecessary communications, monitor for unusual agent activity, and investigate unexpected executable files or processes launched by security-agent components.
Organizations should also examine endpoint telemetry for suspicious child processes, unauthorized downloads, and anomalous network communications.
With both vulnerabilities receiving critical severity ratings, delaying remediation could leave trusted endpoint-security infrastructure exposed to attackers seeking privileged execution.
No Comment! Be the first one.