{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/watchguard-ap--3.4.8/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:h:watchguard:ap:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-101891"},{"id":"CVE-2026-86102"},{"id":"CVE-2026-87969"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WatchGuard AP (\u003c 3.4.8)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","networking","watchguard"],"_cs_type":"advisory","_cs_vendors":["WatchGuard"],"content_html":"\u003cp\u003eWatchGuard has released a security advisory addressing multiple critical vulnerabilities affecting WatchGuard AP access points running firmware versions prior to 3.4.8. These flaws present significant risks to network infrastructure integrity and availability.\u003c/p\u003e\n\u003cp\u003eThe vulnerabilities include CVE-2026-101891, an improper access control flaw in the device API service that permits unauthenticated access. Additionally, CVE-2026-86102 enables command injection via the internal management API, potentially allowing attackers to execute unauthorized commands. Finally, CVE-2026-87969 involves an authenticated command injection vulnerability within the diagnostic Command Line Interface (CLI). Successful exploitation of these vulnerabilities could result in full device compromise, enabling attackers to gain unauthorized persistence within the managed network environment. Administrators are advised to update affected hardware to firmware version 3.4.8 or later immediately.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows for unauthorized access and arbitrary command execution on WatchGuard access points. Given their role in enterprise network access, compromised APs could facilitate further lateral movement, traffic interception, or the permanent disruption of network services.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the firmware update to version 3.4.8 or later on all impacted WatchGuard AP units as documented in the WatchGuard PSIRT advisory.\u003c/li\u003e\n\u003cli\u003eRestrict network management access to AP devices to authorized administrative subnets only.\u003c/li\u003e\n\u003cli\u003eAudit logs for anomalous POST requests or diagnostic CLI activity on networking hardware.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T22:22:16Z","date_published":"2026-09-29T22:22:16Z","id":"https://feed.craftedsignal.io/briefs/2026-09-watchguard-ap-vulnerabilities/","summary":"Multiple vulnerabilities in WatchGuard AP firmware versions prior to 3.4.8, including improper access control and command injection, could allow unauthenticated or authenticated attackers to execute arbitrary commands.","title":"Critical Vulnerabilities in WatchGuard AP Firmware","url":"https://feed.craftedsignal.io/briefs/2026-09-watchguard-ap-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - WatchGuard AP (\u003c 3.4.8)","version":"https://jsonfeed.org/version/1.1"}