OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-86102

CRITICAL · CVSS 9.3 EPSS 1.98%

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

An OS command injection vulnerability in the WatchGuard AP internal API service allows attackers with network access to execute arbitrary shell commands on the underlying operating system. This critical flaw poses a significant risk, potentially leading to unauthorized access and control over affected devices. Organizations using WatchGuard access points should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-86102
Severity
CRITICAL
CVSS
9.3
EPSS
1.98%

Original NVD Description

An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.