• PATCH AVAILABLE

CVE-2026-86102: pre-auth remote command injection in WatchGuard WatchGuard AP

An unauthenticated attacker with network access to a WatchGuard AP can execute arbitrary shell commands on the device, resulting in remote code execution (CVE-2026-86102). The flaw affects WatchGuard AP 3.x releases from 1.0 up to but not including 3.4.8; the vendor fixed the issue in 3.4.8. An attacker only needs network reachability to the AP’s internal API service to exploit the vulnerability—no credentials or user interaction are required.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 4.0
9.3CRITICAL
EPSS
0.01824
CWE
CWE-78
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a pre-auth remote command injection that lets an attacker run shell commands if they can reach the AP’s internal API; upgrade to 3.4.8 immediately or block access to the API from untrusted networks.

What is CVE-2026-86102?

An unauthenticated attacker with network access to a WatchGuard AP can execute arbitrary shell commands on the device, resulting in remote code execution (CVE-2026-86102). The flaw affects WatchGuard AP 3.x releases from 1.0 up to but not including 3.4.8; the vendor fixed the issue in 3.4.8. An attacker only needs network reachability to the AP’s internal API service to exploit the vulnerability—no credentials or user interaction are required. The weakness is classified as CWE-78 (OS Command Injection).

Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Which versions of WatchGuard WatchGuard AP are affected?

BRANCHAFFECTEDFIXED
3.x1.0 – before 3.4.83.4.8

Is CVE-2026-86102 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-86102

  1. Upgrade affected WatchGuard AP devices to firmware 3.4.8.
  2. If you cannot patch immediately, restrict network access to the AP internal API to trusted management subnets and VPNs.
  3. Apply any vendor-recommended mitigations and configuration changes from WatchGuard advisories.
  4. Monitor AP logs and network traffic for unexpected shell command execution or suspicious API requests.

Frequently asked questions

Is CVE-2026-86102 being actively exploited?

There are no public reports of exploitation as of 2026-09-30.

Which WatchGuard AP versions are affected by CVE-2026-86102?

WatchGuard AP 3.x releases from 1.0 up to but not including 3.4.8 are affected; the issue is fixed in 3.4.8.

Is there a patch for CVE-2026-86102?

Yes. WatchGuard fixed the vulnerability in firmware version 3.4.8.

Does CVE-2026-86102 require authentication?

No. The vulnerability can be exploited by an attacker with network access to the AP’s internal API without credentials.

References