TL;DR
WatchGuard patched two critical flaws in its WatchGuard Agent for Windows. Both enable unauthenticated remote code execution. CVE-2026-57909 scores 9.4, and CVE-2026-57910 scores 9.3. Update to version 1.25.13.0000 now.
- Product: WatchGuard Agent
- Vulnerabilities: 2 flaws (CVE-2026-57909, CVE-2026-57910)
- Highest severity: 9.4 (Critical · CVSSv4)
- Worst impact: path traversal allows unauthenticated remote code execution
- Status: No confirmed exploitation yet; patches available
- Action: Update to 1.25.13.0000 now
| CVE | CVSS | Fixed in | Status |
|---|
Why This WatchGuard Agent Vulnerability Matters
WatchGuard Agent runs on Windows endpoints as part of the company’s endpoint protection. A break here hands attackers the very host meant to defend it. Both bugs allow full compromise with no login.
Each WatchGuard Agent vulnerability carries a near-maximum CVSS score. Because an attacker needs no credentials, the barrier to attack is low. As a result, exposed agents face serious risk.
How the Attacks Work
The first flaw is a path traversal issue, tracked as CVE-2026-57909. WatchGuard says it lets an attacker execute arbitrary code on an affected system.
The attacker must sit on an adjacent network.
The second flaw, CVE-2026-57910, stems from improper authentication. Attackers abuse the UDP discovery service and a task handler. Consequently, the agent downloads and runs an attacker-controlled program. WatchGuard notes this runs code with elevated privileges,
often as SYSTEM.
Is It Being Exploited?
No exploitation in the wild has been confirmed. For both bugs, WatchGuard states it is not aware of any exploitation of this vulnerability in the wild.
Likewise, no public proof-of-concept exists yet.
Affected Versions
All WatchGuard Agent builds for Windows before 1.25.13.0000 are affected. Version 1.25.13.0000 and later are not.
Patch and Mitigation Steps
Upgrade to WatchGuard Agent 1.25.13.0000 right away. You can review the details in the advisories for CVE-2026-57909 and CVE-2026-57910. Until you patch, limit network access to agent hosts and watch for odd UDP traffic.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!