CVE-2026-6787Patch(watchguard / agent)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch watchguard agent systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Use of Hard-coded Cryptographic Key vulnerability in WatchGuard Agent on Windows allows Inclusion of Code in Existing Process.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-321

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • agent

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-05-07); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
agent

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-05-06: 2Mentions · 2026-05-07: 3Mentions · 2026-05-14: 1Mentions · 2026-05-20: 1PoC Mentioned / Linked · 2026-05-07: 1Patch / Workaround · 2026-05-07: 3Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-06: 2Technical Details · 2026-05-07: 3Technical Details · 2026-05-14: 105-0605-0705-1405-20
Signal classification2 categories
Patch
457.1%
Disclosure
342.9%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-062
Disclosure2
2026-05-073
Patch3
2026-05-141
Patch1
2026-05-201
Disclosure1
Full discourse7 posts
  • yousukezan@yousukezan
    Patch

    WatchGuardは、Windows版WatchGuard Agentに存在する複数の脆弱性を修正する緊急アップデートを公開した。最も深刻なのはCVE-2026-6787とCVE-2026-6788で、研究者は両脆弱性を連鎖利用することで、ローカルの一般ユーザーがNT AUTHORITY\SYSTEM権限を取得できることを確認した。これにより、攻撃者はWindows端末を完全制御可能となる。 さらにCVE-2026-41288では、パッチ管理コンポーネントにおける不適切な権限設定が問題となった。認証済みローカルユーザーがサービスを操作し、SYSTEM権限へ昇格できる。セキュリティ更新機能自体が攻撃経路として悪用される点が危険視されている。 加えて、WatchGuard Agent Discovery Serviceにはスタックベースのバッファオーバーフロー脆弱性CVE-2026-41286およびCVE-2026-41287も存在していた。これらは同一ネットワーク上の未認証攻撃者が悪用可能で、細工したデータを送信することでエージェントサービスをクラッシュさせられる。 影響はDoSに分類されるが、セキュリティエージェント停止によって監視機能が無効化され、別の不正活動を見逃す危険がある。WatchGuardは、これら脆弱性に対する実用的な回避策は存在せず、公式アップデート適用が唯一の対策だとしている。 管理者には、全Windows端末へWatchGuard Agent 1.25.03.0000を速やかに展開するよう強く推奨されている。 https://securityonline.info/watchguard-agent-windows-privilege-escalation-cve-2026-6787-system-takeover/

    Post summary

    WatchGuard released an emergency patch to fix multiple privilege‑escalation and buffer‑overflow CVEs (CVE‑2026‑6787/6788, CVE‑2026‑41286/41287/41288) that could allow local or unauthenticated users to gain SYSTEM rights or cause DoS; applying the official update is the only mitigation.

    0401523.7K
    14.4K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    WatchGuard Agent v1.25.03.0000 fixes critical privilege escalation flaws (CVE-2026-6787) and buffer overflows. Secure your Windows endpoints and patch now! #WatchGuard #CyberSecurity #InfoSec #WindowsSecurity #PrivilegeEscalation #SystemTakeover https://securityonline.info/watchguard-agent-windows-privilege-escalation-cve-2026-6787-system-takeover/ https://t.co/N9tc5E58Jv

    Post summary

    The post announces that WatchGuard Agent v1.25.03.0000 addresses CVE‑2026‑6787 privilege‑escalation and buffer‑overflow flaws, and urges immediate patching.

    02080584
    12.5K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    権限昇格2件とDoS2件 CVE-2026-6787, CVE-2026-6788 CVE-2026-41288 CVE-2026-41286 CVE-2026-41287 Security Advisories | WatchGuard Technologies https://www.watchguard.com/wgrd-psirt/advisories

    Post summary

    The note enumerates several CVEs affecting WatchGuard products, noting privilege‑escalation and DoS vulnerabilities, and links to the vendor’s security advisories page for patch information.

    00020330
    6.9K followersView on X
  • iototsecnews@iototsecnews
    Patch

    WatchGuard Agent for Windows の複数の脆弱性が FIX:SYSTEM 権限取得の恐れ https://iototsecnews.jp/2026/05/07/watchguard-agent-flaws-allow-attackers-to-gain-full-system-privileges-on-windows/ 今回の脆弱性の原因は、プログラム内部での権限管理やメモリ処理の不備にあります。 CVE-2026-6787/CVE-2026-6788 では複数の小さな不具合が連鎖したことが原因で、また、CVE-2026-41288 ではリソースへの権限割り当てミスが原因で、本来制限されるべき一般ユーザーが管理者権限を得られる状態になっていました。また、 CVE-2026-41286/CVE-2026-41287 では、外部からのデータを受け取る際のメモリ領域の確認が不十分だったことで、サービス停止を招くバッファ・オーバーフローが発生しています。ご利用のチームは、ご注意ください。 #AgentforWindows #CVE20266787 #CVE20266788 #Vulnerability #WatchGuard

    Post summary

    The post reports that several WatchGuard Agent for Windows CVEs that enable privilege escalation and buffer overflows have been fixed, but it gives no exploit code or active usage evidence.

    01000110
    491 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6787 Use of Hard-coded Cryptographic Key vulnerability in WatchGuard Agent on Windows allows Inclusion of Code in Existing Process.This issue affects WatchGuard Agent: befor… https://www.cve.org/CVERecord?id=CVE-2026-6787

    Post summary

    The snippet announces CVE‑2026‑6787, describing a hard‑coded cryptographic key flaw in WatchGuard Agent that could enable code inclusion, but it offers no PoC, exploit code, or patch information.

    00010132
    57.4K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos WatchGuard ❗ CVE-2026-6788 ❗ CVE-2026-6787 ❗ CVE-2026-41288 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-watchguard-4/ https://t.co/8UkUk2fooU

    Post summary

    The post announces WatchGuard product vulnerabilities (CVE‑2026‑6788, CVE‑2026‑6787, CVE‑2026‑41288) and directs readers to an official CERT Paraguay page for additional details.

    00000117
    6.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6787 Use of Hard-coded Cryptographic Key vulnerability in WatchGuard Agent on Windows allows Inclusion of Code in Existing Process.This issue affects WatchGuard Agent: befor… https://www.cve.org/CVERecord?id=CVE-2026-6787 ----- Traducción: CVE-2026-6787 Uso… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑6787, describing a hard‑coded cryptographic key flaw that permits code inclusion in an existing process, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    0000032
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwatchguardagent-windows-

Explore more