CVE-2026-41287Disclosure(watchguard / agent)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch watchguard agent systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local network could exploit this vulnerability to crash the agent service.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • agent

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-05-06); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
agent

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-06: 2Mentions · 2026-05-07: 1Mentions · 2026-05-14: 1Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-06: 2Technical Details · 2026-05-07: 1Technical Details · 2026-05-14: 105-0605-0705-14
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-062
Disclosure2
2026-05-071
General1
2026-05-141
Patch1
Full discourse4 posts
  • Autumn Good@autumn_good_35
    General

    権限昇格2件とDoS2件 CVE-2026-6787, CVE-2026-6788 CVE-2026-41288 CVE-2026-41286 CVE-2026-41287 Security Advisories | WatchGuard Technologies https://www.watchguard.com/wgrd-psirt/advisories

    Post summary

    The content lists WatchGuard CVEs associated with privilege escalation and DoS issues but provides no PoC, exploit, active exploitation, or patch details.

    00020330
    6.9K followersView on X
  • iototsecnews@iototsecnews
    Patch

    WatchGuard Agent for Windows の複数の脆弱性が FIX:SYSTEM 権限取得の恐れ https://iototsecnews.jp/2026/05/07/watchguard-agent-flaws-allow-attackers-to-gain-full-system-privileges-on-windows/ 今回の脆弱性の原因は、プログラム内部での権限管理やメモリ処理の不備にあります。 CVE-2026-6787/CVE-2026-6788 では複数の小さな不具合が連鎖したことが原因で、また、CVE-2026-41288 ではリソースへの権限割り当てミスが原因で、本来制限されるべき一般ユーザーが管理者権限を得られる状態になっていました。また、 CVE-2026-41286/CVE-2026-41287 では、外部からのデータを受け取る際のメモリ領域の確認が不十分だったことで、サービス停止を招くバッファ・オーバーフローが発生しています。ご利用のチームは、ご注意ください。 #AgentforWindows #CVE20266787 #CVE20266788 #Vulnerability #WatchGuard

    Post summary

    The article reports that patches have been released for several privilege‑escalation and buffer‑overflow vulnerabilities in WatchGuard Agent for Windows, outlining the underlying causes such as incorrect privilege assignments and insufficient memory checks.

    01000110
    491 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-41287 Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local … https://www.cve.org/CVERecord?id=CVE-2026-41287 ----- Traducción: CVE-2026-41287 Des… http://infoflow.cloud`

    Post summary

    A stack-based buffer overflow vulnerability (CVE-2026-41287) affects the WatchGuard Agent discovery service on Windows, as disclosed via the CVE record link, with no mention of PoC, exploit, patch, or active exploitation.

    0000030
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41287 Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local … https://www.cve.org/CVERecord?id=CVE-2026-41287

    Post summary

    The text announces a stack-based buffer overflow in the WatchGuard Agent discovery service (CVE‑2026‑41287), providing only the vulnerability type and affected component without any PoC, exploit, or remediation information.

    00000122
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwatchguardagent-windows-

Explore more