← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 26, 2026 · 12:33via CyberPress

Critical WatchGuard Agent Flaws Let Remote Attackers Execute Arbitrary Code

Brief

WatchGuard has disclosed two critical vulnerabilities in its Windows-based WatchGuard Agent that could allow unauthenticated attackers to execute arbitrary code on vulnerable endpoints.

The flaws, tracked as CVE-2026-57910 and CVE-2026-57909, affect WatchGuard Agent versions earlier than 1.

  • 13. 0000 and carry CVSS v4. 0 scores of 9. 3 and 9. 4, respectively.

Both vulnerabilities were published on August 25, 2026. Although WatchGuard said it is not aware of exploitation in the wild, the issues create a serious exposure for organizations operating unpatched endpoint protection deployments.

Critical WatchGuard Agent Flaws

CVE-2026-57910 is an improper authentication vulnerability that enables an unauthenticated attacker with network access to force the WatchGuard Agent to execute attacker-controlled code with elevated privileges.

Read more on CyberPress