CVE-2026-86102
An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.
- Published Sep 28, 2026
- CVSS 9.3 critical
- 2.0% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- ⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests The Hacker News ·
- WatchGuard Patches Critical Fireware OS Code Injection Vulnerability SecurityWeek ·
- WatchGuard security advisory (AV26-972) Canadian Centre for Cyber Security ·