CVE-2026-101891
An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.
- Published Sep 28, 2026
- CVSS 9.3 critical
- 0.3% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- ⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests The Hacker News ·
- WatchGuard Patches Critical Fireware OS Code Injection Vulnerability SecurityWeek ·
- WatchGuard security advisory (AV26-972) Canadian Centre for Cyber Security ·