Description
A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.
Published: 2026-08-25
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The WatchGuard Agent contains a path traversal flaw that enables an unauthenticated attacker on a nearby network to execute arbitrary code on the target machine. This flaw allows the attacker to bypass authorization checks and manipulate file paths, meeting the criteria of CWE-306 and CWE-94, and ultimately achieve full system compromise, affecting confidentiality, integrity, and availability.

Affected Systems

The vulnerability affects all versions of WatchGuard Agent prior to 1.25.13.0000. Devices running the older, unpatched WatchGuard Agent software are susceptible to exploitation.

Risk and Exploitability

The CVSS base score of 9.4 indicates a critical risk, while an absent EPSS score does not imply low exploitation probability but suggests no recent known exploits. Because the flaw allows unauthenticated remote exploitation, an attacker with network visibility could launch the payload without further credentials. Once exploited, the attacker can execute arbitrary commands with system privileges, thereby creating a persistent foothold. The lack of a KEV listing indicates that there are currently no confirmed widespread attacks, but the high severity justifies immediate action.

Generated by OpenCVE AI on August 25, 2026 at 13:50 UTC.

Remediation

Vendor Solution

WatchGuard Agent 1.25.13.0000


OpenCVE Recommended Actions

  • Upgrade to WatchGuard Agent 1.25.13.0000 immediately.
  • Restrict the WatchGuard Agent’s remote access to a secure, isolated network segment and disable any unnecessary remote services.
  • Monitor network traffic and device logs for suspicious activity and block incoming connections from unknown sources using firewall rules.

Generated by OpenCVE AI on August 25, 2026 at 13:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Watchguard agent
Vendors & Products Watchguard agent

Tue, 25 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.
Title WatchGuard Agent path traversal allows unauthenticated remote code execution
First Time appeared Watchguard
Watchguard watchguard Agent
Weaknesses CWE-306
CWE-94
CPEs cpe:2.3:a:watchguard:watchguard_agent:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard watchguard Agent
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Watchguard Agent Watchguard Agent
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-26T13:16:42.462Z

Reserved: 2026-06-26T09:41:49.464Z

Link: CVE-2026-57909

cve-icon Vulnrichment

Updated: 2026-08-25T12:53:42.643Z

cve-icon NVD

Status : Deferred

Published: 2026-08-25T12:16:24.617

Modified: 2026-08-28T18:43:25.883

Link: CVE-2026-57909

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T14:00:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')