CVE-2026-86102criticalCWE-78CWE-863

CVE-2026-86102: critical vulnerability in WatchGuard AP

WatchGuard AP Command Injection in Internal Management API Allows Command Execution

Published

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.3epss 2.0%
exploitation probability
2.0%top 20% of all CVEs
observed exploitation
nono source reports it
An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N