OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-101891

CRITICAL · CVSS 9.3 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

An improper access control vulnerability in an internal API service on WatchGuard Access Points allows unauthenticated attackers with network access to gain a valid API session, potentially leading to unauthorized access and manipulation of sensitive configurations. Organizations utilizing WatchGuard Access Points should prioritize this critical vulnerability to mitigate risks of unauthorized network access and potential exploitation. Immediate action is recommended to secure affected devices and prevent potential breaches.

CVE
CVE-2026-101891
Severity
CRITICAL
CVSS
9.3
EPSS
0.27%

Original NVD Description

An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.