CVE-2026-101891

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-923

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-09-29); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-09-29: 1Mentions · 2026-09-30: 109-2909-30
Referenced assets2 URLs
Full discourse2 posts
  • CCB Alert@CCBalert

    Warning: 2 Critical vulnerabilities in #WatchGuard v3.4.8. #CVE-2026-86102 #CVE-2026-101891 CVSS: 9.3. A remote attacker without privileges or user interaction can exploit them to obtain a valid API session & execute arbitrary shell commands. https://ccb.belgium.be/advisories/warning-two-critical-vulnerabilities-which-can-lead-remote-code-execution-watchguard #Patch #Patch

    01100207
    7.3K followersView on X
  • Cybersecurity News DE@cybsecuritynews

    #schwachstellen WatchGuard Access Points: Kritische Lücke CVE-2026-101891 erlaubt API-Sitzung ohne Anmeldung #cve2026101891 #watchguard #watchguardaccesspoints https://cybersecurity-news.de/watchguard-access-points-cve-2026-101891

    0000019
    14 followersView on X

Explore more