CVE-2026-86102

Summary

An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.

Affected Software

VendorProductVersion RangeStatus
WatchGuardWatchGuard AP1.0 < 3.4.8affected

Weaknesses

  • CWE-78: CWE-78
  • CWE-863: CWE-863

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References