CVE-2026-86102: critical vulnerability in WatchGuard AP
WatchGuard AP Command Injection in Internal Management API Allows Command Execution
Published
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.3epss 2.0%
exploitation probability
2.0%top 20% of all CVEs
observed exploitation
nono source reports it
An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
WatchGuard · WatchGuard APRelated CVEs — WatchGuard AP
In the same product, most dangerous first.