CVE-2026-95676: WatchGuard Authentication Gateway
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Additional authentication factors still apply.
Affected products
- WatchGuard Authentication Gateway: from 4.2.2, before 7.5.1 (fixed in 7.5.1)
Published 2026-09-23. Last modified 2026-10-07.