CVE-2026-57909: WatchGuard Agent path traversal allows unauthenticated remote code execution
Published Aug 25, 2026
·Updated
A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.
Affected Software
1 affected component
WatchGuard WatchGuard Agent
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Agentto a version that resolves this vulnerability.Fixed in 1.25.13.0000Patch WatchGuard Agent path traversal allows unauthenticated remote code execution
Event History
Aug 25, 2026
CVE Published
via MITRE·11:47 AM
Data Sourced
via MITRE·11:47 AM
RemedyDescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must be on an adjacent network and does not need to authenticate. The issue affects systems running WatchGuard Agent.
2
What level of access could exploitation provide?
Successful exploitation allows arbitrary code execution on the affected system.