WatchGuard disclosed three vulnerabilities affecting WatchGuard AP firmware versions 1.0 through 3.4.7, including two critical unauthenticated flaws: CVE-2026-86102 and CVE-2026-101891. Both carry a CVSS v4 score of 9.3 and can allow a network-based attacker to bypass authentication or execute arbitrary operating-system commands through exposed internal API functionality. A third issue, CVE-2026-87969 (CVSS 8.6), enables authenticated administrators to inject and execute OS commands through crafted diagnostic command-line input.
WatchGuard fixed all three vulnerabilities in firmware version 3.4.8. The company reported no known in-the-wild exploitation or public proof of concept at disclosure, but the unauthenticated network-reachable attack paths make unpatched APs high-risk. Organizations should immediately upgrade affected devices, restrict AP management and API interfaces to trusted administrative networks, and review logs and administrator credentials for signs of unauthorized access.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
WatchGuard disclosed CVE-2026-86102 and CVE-2026-101891, critical unauthenticated internal-API flaws that permit command execution or access-control bypass, plus CVE-2026-87969, an authenticated diagnostic CLI command-injection flaw. The issues affect AP firmware versions 1.0 through 3.4.7 and were fixed in firmware version 3.4.8; no active exploitation was publicly known at disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourcecybersecuritynews.com
Open sourceheise.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.