Threat intelligence dashboard
CVE-2026-86102critical

WatchGuard AP Command Injection in Internal Management API Allows Command Execution

An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.

Risk score

9.3

CVSS 4.0

Vendor
WatchGuard
Product
WatchGuard AP
CWE
CWE-78, CWE-863
Published
Sep 28, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

WatchGuard AP

WatchGuard

Version / rangeStatusType
1.0 to before 3.4.8affectedsemver

Technical metrics

9.3

CVSS 4.0

Severity
critical
Source
WatchGuard
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N