CVE-2026-57909: WatchGuard Agent

Critical severity, CVSS 9.4. EPSS: 0.4% chance of exploitation in the next 30 days.

A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.

Affected products

  • WatchGuard WatchGuard Agent: before 1.25.13.0000 (fixed in 1.25.13.0000)

Published 2026-08-25. Last modified 2026-09-28.