Serial number: AV26-972
Date: September 29, 2026
As of September 28, 2026, WatchGuard is affected by vulnerabilities in the following product:
- WatchGuard AP
- Prior to 3.4.8
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- CVE-2026-101891 — WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access
- CVE-2026-86102 — WatchGuard AP Command Injection in Internal Management API Allows Command Execution
- CVE-2026-87969 — WatchGuard AP Authenticated Command Injection in Diagnostic CLI
- WatchGuard Security Advisories