CriticalCritical vulnerability
CVE-2026-86102 (CVSS 9.3)
NVD · officialPublished Sep 28, 2026Risk 50/100
An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.
Technical details
CVSS
9.3
AV:NetworkAC:LowPR:NoneUI:None
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source