WatchGuard Patches Critical API Flaws in Access Points Allowing Unauthenticated Command Execution
WatchGuard has issued a firmware update addressing three vulnerabilities in its access points, two of which are rated critical and allow unauthenticated command execution on the device operating system.
The flaws affect firmware versions 1.0 through 3.4.7, with the fix available in version 3.4.8. The most severe issue, tracked as CVE-2026-86102 and rated 9.3 on the CVSS scale, is a command injection vulnerability in the internal API management service. An attacker with network access to a vulnerable device can trigger arbitrary shell commands without any authentication, valid session, or administrator interaction.
The second critical flaw, CVE-2026-101891, also scored at 9.3, stems from improper access control in the same internal service. It enables an unauthenticated attacker to interact with protected management functions, potentially leading to full device or network compromise.
The third vulnerability, CVE-2026-87969, carries a CVSS score of 8.6 and involves command injection via the command-line diagnostic interface. Unlike the other two issues, it requires authenticated administrator privileges to exploit.
Beyond the individual devices, a compromised access point can act as a persistent foothold inside corporate networks, providing visibility into traffic and a launch point for lateral movement against other systems.
The vulnerabilities were publicly disclosed on September 28. At the time of disclosure, no evidence of active exploitation or publicly available proof-of-concept code had been identified. Organizations are advised to update affected access points to firmware version 3.4.8 as soon as possible.
Related articles
Critical Vulnerability CVE-2026-12342 Allows Remote Code Execution in SailPoint IdentityIQ
SailPoint has disclosed a critical vulnerability in its identity management product IdentityIQ that stems from insufficient input validation in the web service API. The flaw, identified as CVE-2026-12342, permits an attacker on an adjacent network to execute arbitrary code on the IdentityIQ server without requiring authentication. The vulnerability received a CVSSv3.1 base score of 9.6 and is rated Critical. SailPoint published a security advisory on September 28, 2026, and has released patches for all supported affected versions. The company also plans to include the fix in future patch levels. The issue affects the processing of content sent to the web service API, where improper validation allows malicious input to trigger code execution.
Spectre Variant Returns: Branch Target Reuse Attack Extracts Root Password Hash from Linux Memory
Researchers from VUSec and Scuola Superiore Sant’Anna have disclosed Branch Target Reuse, a new Spectre v2 variant that exploits stale branch predictor entries in modern CPUs. The attack targets JIT compilers that generate and reuse executable code at runtime, allowing speculative execution of instructions from previously freed memory regions. On Intel systems with existing mitigations enabled, the researchers demonstrated extraction of the root password hash from the Linux kernel in minutes. Practical proof-of-concept exploits were developed against the Linux kernel, while PoCs were also prepared for Firefox and tested on GraalVM. The issue affects Intel, AMD, and Arm processors, although exploitation success depends on the specific JIT environment and predictor state. Defenses have already been merged into the Linux kernel and GraalVM, while Mozilla continues work on site isolation. The findings highlight that Spectre-class issues remain relevant as long as processors rely on aggressive speculative execution.
EASM Uncovers Forgotten Perimeter Assets Including 11-Year-Old Servers Invisible to Standard Scanners
EASM solutions continuously discover external attack surfaces by starting from public data such as company names, domains, WHOIS records, Certificate Transparency logs, and internet-wide scanners like Shodan and Censys. Unlike traditional vulnerability scanners that only check assets from a predefined list, EASM maps unknown shadow IT including forgotten test servers, abandoned marketing subdomains, exposed APIs, and cloud buckets left open to the internet. The technology follows the same reconnaissance path used by attackers and has become essential for mature vulnerability management programs after years of being considered exotic. Major vendors including Palo Alto Networks Cortex Xpanse, CyCognito, Qualys, Rapid7, and Tenable now lead the market, while Russian providers such as Positive Technologies PT EASM, BI.ZONE EASM, and CyberOK PenOps have grown rapidly since 2022. Without an established process for prioritization and remediation, EASM implementations risk generating overwhelming alert volumes rather than reducing risk. The approach is now viewed as a core component of Continuous Threat Exposure Management (CTEM) frameworks.
Mozilla Releases Firefox 157 with 76 Security Fixes, Shifts to Individual CVE Reporting
Mozilla Foundation has released Firefox 157, addressing 76 vulnerabilities rated at various severity levels. The update also includes patches for the extended support releases Firefox ESR 153.4, ESR 140.17, and ESR 115.42. A key change in this release involves Mozilla's new approach to publishing security advisories, moving from grouping multiple memory safety issues under single CVEs to reporting them individually. Among the high-severity issues fixed are sandbox escape flaws, privilege escalation bugs, use-after-free errors, uninitialized memory problems, and JIT compiler mistakes affecting components such as DOM, Graphics, WebGPU, WebAssembly, and Networking. The ESR versions received 62, 43, and 31 fixes respectively, with 34 rated high in the latest branch. All listed CVEs range from CVE-2026-100756 through CVE-2026-100831.