CVE-2026-57909Patch

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 7 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-08-27); latest day: 1
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-08-26: 1Mentions · 2026-08-27: 5Mentions · 2026-09-03: 1Patch / Workaround · 2026-08-26: 1Patch / Workaround · 2026-08-27: 3Patch / Workaround · 2026-09-03: 1Technical Details · 2026-08-26: 1Technical Details · 2026-08-27: 5Technical Details · 2026-09-03: 108-2608-2709-03
Signal classification3 categories
Patch
571.4%
Disclosure
114.3%
General
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-08-261
Patch1
2026-08-275
Disclosure1General1Patch3
2026-09-031
Patch1
Full discourse7 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Two critical WatchGuard Agent flaws (CVE-2026-57909, CVE-2026-57910) allow unauthenticated remote code execution. Update to 1.25.13.0000 now. #WatchGuard #RCE #CyberSecurity #CVE202657909 #Infosec https://securityonline.info/watchguard-agent-rce-vulnerability/

    Post summary

    Two critical unauthenticated RCE vulnerabilities (CVE-2026-57909, CVE-2026-57910) have been disclosed, and users are advised to update to WatchGuard Agent version 1.25.13.0000.

    050174990
    13.0K followersView on X
  • キタきつね@foxbook
    General

    CVE-2026-57909: WatchGuardエージェントによる認証なしのリモートコード実行 CVE-2026-57909: WatchGuard Agent Unauthenticated Remote Code Execution #DailyCyberSecurity (Aug 26) https://securityonline.info/watchguard-agent-rce-vulnerability/

    Post summary

    The post simply announces a WatchGuard Agent unauthenticated RCE vulnerability with no details on exploits, patches, or active attacks.

    00031342
    5.0K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical #RCE flaws in #WatchGuard #Agent. #CVE-2026-57909 CVSS: 9.4. #CVE-2026-57910 CVSS: 9.3. Unauthenticated attackers can execute arbitrary code! Upgrade to 1.25.13.0000. See CCB advisory at https://ccb.belgium.be/advisories/warning-remote-code-execution-vulnerabilities-watchguard-agent-patch-immediately #Patch #Patch #Patch

    Post summary

    The post announces two critical CVEs affecting WatchGuard Agent, details their severity, and urges users to apply the 1.25.13.0000 patch immediately.

    02000387
    7.2K followersView on X
  • Cyber Edition@CyberEdition
    Patch

    🚨 Two critical WatchGuard Agent flaws, CVE-2026-57909 and CVE-2026-57910, could let unauthenticated attackers execute code on Windows endpoints. WatchGuard urges users to update to Agent 1.25.13.000 or later. #CyberSecurity #Windows Read more: https://thecyberedition.com/critical-watchguard-agent-flaws-enable-unauthenticated-code-execution-on-windows-endpoints/

    Post summary

    The tweet alerts users to two critical WatchGuard Agent CVEs that enable unauthenticated code execution on Windows with an immediate patch recommendation.

    00010131
    767 followersView on X
  • iototsecnews@iototsecnews
    Patch

    WatchGuard Agent のCVE-2026-57910/57909 が FIX:RCE による root/SYSTEM 権限取得の恐れ https://iototsecnews.jp/2026/08/26/critical-watchguard-agent-flaws-let-unauthenticated-attackers-execute-remote-code/ WatchGuard Agent に脆弱性 CVE-2026-57910/CVE-2026-57909 が発見されました。その背景にあるのは、認証処理の不足やパス階層の検証不備です。その結果、未認証の第三者による遠隔からの任意コード実行/最上位権限でのホスト全域に対する完全な操作/機密情報の流出/マルウェアの常駐/内部ネットワークへの侵入拡大などの深刻な影響が生じます。最新版への迅速な更新/稼働端末におけるバージョン情報の確認/検出サービスの不審な UDP 通信監視/異常プロセス起動の追跡といった多角的な安全確保処置が求められます。 #CVE202657909 #CVE202657910 #Vulnerability #WatchGuard

    Post summary

    The notice announces the discovery of CVE-2026‑57910 and CVE-2026‑57909 in WatchGuard Agent, details an RCE that permits full system control, and urges immediate patching and complementary security checks.

    00000126
    510 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 『A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code』 CVE-2026-57909 — WatchGuard Agent path traversal allows unauthenticated remote code execution https://psirt.watchguard.com/CVE-2026-57909/

    Post summary

    The tweet announces CVE‑2026‑57909, a path traversal flaw in WatchGuard Agent that allows unauthenticated remote code execution, without mentioning any PoC, exploit, or patch details.

    00000444
    7.0K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    WatchGuard Agentに認証不要RCE 脆弱性 2件 CVE-2026-57909/57910、Windows版1.25.13.0000で修正 https://rocket-boys.co.jp/security-measures-lab/watchguard-agent-unauthenticated-rce-vulnerabilities-cve-2026-57909/ #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性

    Post summary

    The article reports that WatchGuard Agent suffers from two unauthenticated RCE vulnerabilities (CVE‑2026‑57909/57910) that have already been addressed in Windows version 1.25.13.0000.

    00000181
    554 followersView on X

Explore more