TL;DR
On September 29, 2026, WatchGuard disclosed three severe WatchGuard AP vulnerabilities. These flaws allow attackers to bypass authentication and execute arbitrary operating system commands. Network administrators must update their access points to version 3.4.8 immediately to secure their wireless infrastructure.
- Total: 3 CVEs
- Severity: 2 Critical · 1 High
- Actively exploited: None confirmed
- Highest severity: 9.3 (Critical · CVSSv4) — CVE-2026-101891
- Action: Apply the latest security updates now
See a CVE's exploit risk spike before it becomes a headline.
Get EPSS spike alertsNotable CVEs
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-101891 | 9.3 | Improper Access Control in API Service Allows Unauthenticated Access | 3.4.8 | Not exploited |
| CVE-2026-86102 | 9.3 | Command Injection in Internal Management API Allows Command Execution | 3.4.8 | Not exploited |
| CVE-2026-87969 | 8.6 | Authenticated Command Injection in Diagnostic CLI | 3.4.8 | Not exploited |
Why It Matters
Sourced estimates show that thousands of enterprise networks rely on WatchGuard access points for wireless connectivity. Security defects in these network edge devices expose internal traffic to severe risks. Two of these flaws carry critical CVSS base scores of 9.3. An unauthenticated attacker can hijack the internal management API to gain full device control. Currently, the vendor has not observed any active exploitation of these WatchGuard AP vulnerabilities in the wild. Furthermore, researchers have not published any public proof-of-concept exploit code. However, unpatched wireless access points remain highly vulnerable to complete system compromise.
How The Attack Works
These defects target the diagnostic command-line interface and internal API services. CVE-2026-101891 involves improper access control within an internal API. An unauthenticated attacker on the same network can obtain a valid API session.
Once authenticated, attackers can exploit an OS command injection flaw tracked as CVE-2026-86102. The internal API service fails to sanitize special elements properly. Consequently, an attacker can execute arbitrary shell commands directly on the underlying operating system. Additionally, CVE-2026-87969 allows an authenticated administrator to trigger a similar command injection via the diagnostic CLI.
Affected Versions
These security flaws impact a wide range of firmware releases. Specifically, they affect WatchGuard AP versions starting from 1.0 up to, but not including, version 3.4.8.
Patch Or Mitigation Steps
Network administrators must apply the latest vendor firmware updates without delay. WatchGuard addressed all three flaws in version 3.4.8. Securing your access points stops intruders from executing unauthorized commands on your network hardware.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!