CVE-2026-13043
A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process memory.
- Published Oct 1, 2026
- CVSS 9.3 critical
- 0.1% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- WatchGuard security advisory (AV26-990) Canadian Centre for Cyber Security ·