<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:watchguard:endpoint_security:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3awatchguardendpoint_security/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 14:12:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3awatchguardendpoint_security/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>WatchGuard Endpoint Security Kernel Driver Authentication Bypass</title><link>https://feed.craftedsignal.io/briefs/2026-10-watchguard-cve-2026-13043/</link><pubDate>Fri, 02 Oct 2026 14:12:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-watchguard-cve-2026-13043/</guid><description>A missing authentication vulnerability in the WatchGuard Endpoint Security kernel memory access driver allows local attackers to perform arbitrary kernel memory access, potentially facilitating privilege escalation.</description><content:encoded><![CDATA[<p>WatchGuard has issued a security advisory regarding a vulnerability identified as CVE-2026-13043 affecting WatchGuard Endpoint Security. The issue stems from missing authentication in the product's kernel memory access driver. An attacker who has already obtained local access to a system can exploit this vulnerability to read or write to arbitrary kernel memory. Successful exploitation of this flaw can lead to local privilege escalation, allowing an attacker to gain elevated permissions on the compromised host. The vulnerability affects all versions of WatchGuard Endpoint Security prior to 8.00.26.0012. Administrators are advised to apply the vendor-supplied security updates immediately.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-13043 allows local attackers to achieve arbitrary kernel memory access, which is a significant security compromise. This level of access typically results in full system compromise, as it enables the bypassing of kernel-level security controls, persistent modification of system data, or escalation of privileges to SYSTEM/root levels. Organizations using affected WatchGuard Endpoint Security versions are exposed to local threats that could leverage this vulnerability to maintain persistence or conduct deeper post-exploitation activities.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the update of all managed systems running WatchGuard Endpoint Security to version 8.00.26.0012 or later. Ensure that internal vulnerability scanning tools are configured to detect the vulnerable versions of the agent based on the product release notes provided by WatchGuard. Focus remediation efforts on high-value targets and shared workstation environments where local user access is more common.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>privilege-escalation</category><category>endpoint-security</category><category>informational</category></item></channel></rss>