<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:h:watchguard:ap:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3hwatchguardap/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 22:22:16 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3hwatchguardap/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical Vulnerabilities in WatchGuard AP Firmware</title><link>https://feed.craftedsignal.io/briefs/2026-09-watchguard-ap-vulnerabilities/</link><pubDate>Tue, 29 Sep 2026 22:22:16 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-watchguard-ap-vulnerabilities/</guid><description>Multiple vulnerabilities in WatchGuard AP firmware versions prior to 3.4.8, including improper access control and command injection, could allow unauthenticated or authenticated attackers to execute arbitrary commands.</description><content:encoded><![CDATA[<p>WatchGuard has released a security advisory addressing multiple critical vulnerabilities affecting WatchGuard AP access points running firmware versions prior to 3.4.8. These flaws present significant risks to network infrastructure integrity and availability.</p>
<p>The vulnerabilities include CVE-2026-101891, an improper access control flaw in the device API service that permits unauthenticated access. Additionally, CVE-2026-86102 enables command injection via the internal management API, potentially allowing attackers to execute unauthorized commands. Finally, CVE-2026-87969 involves an authenticated command injection vulnerability within the diagnostic Command Line Interface (CLI). Successful exploitation of these vulnerabilities could result in full device compromise, enabling attackers to gain unauthorized persistence within the managed network environment. Administrators are advised to update affected hardware to firmware version 3.4.8 or later immediately.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities allows for unauthorized access and arbitrary command execution on WatchGuard access points. Given their role in enterprise network access, compromised APs could facilitate further lateral movement, traffic interception, or the permanent disruption of network services.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Apply the firmware update to version 3.4.8 or later on all impacted WatchGuard AP units as documented in the WatchGuard PSIRT advisory.</li>
<li>Restrict network management access to AP devices to authorized administrative subnets only.</li>
<li>Audit logs for anomalous POST requests or diagnostic CLI activity on networking hardware.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>networking</category><category>watchguard</category></item></channel></rss>