9/28/2026 • Security
WatchGuard AP Flaws: A Free Session for Anyone on Your Network
WatchGuard has patched three flaws in its cloud-managed Wi-Fi access points, two of them rated 9.3. The worst hands an API session to anyone on your LAN, no password needed. Fixed in firmware 3.4.8, not exploited yet.
On 28 September 2026 WatchGuard published three security advisories for its cloud-managed Wi-Fi access points, and the headline one, CVE-2026-101891, is about as blunt as a vulnerability description gets: an internal API on the access point will hand a valid session to anyone on the network who asks for it. No username, no password, nobody to trick into clicking anything. WatchGuard rates it 9.3 out of 10, Critical. Sitting right beside it is a second 9.3, a command-injection flaw in the same internal API that lets an attacker run shell commands on the access point itself.
The good news comes first, because there's a fair bit of it. The fix already exists (firmware 3.4.8, which shipped four days before the advisories), nobody is known to be exploiting any of the three, and WatchGuard found the worst one itself. That's the well-handled version of this story. The part that deserves your attention is where the attacker has to be standing to use it: not out on the internet, but on your own network. For a lot of small businesses, that bar is lower than it sounds.
What happened, in plain English
Three CVEs, one firmware line, one fix. Here's the honest shape of each:
- CVE-2026-101891 (CVSS v4.0 9.3, Critical). An improper access control flaw in an internal API service on the access point. An unauthenticated attacker with network access to the AP can obtain a valid API session. WatchGuard tags it CWE-284 (Improper Access Control) and CWE-923 (a communication channel that isn't properly restricted to the endpoints it was meant for), and it was discovered internally by WatchGuard.
- CVE-2026-86102 (CVSS v4.0 9.3, Critical). An OS command injection flaw in the same internal management API. An attacker with network access to the AP can execute arbitrary shell commands on the underlying operating system. Reported by an external researcher.
- CVE-2026-87969 (CVSS v4.0 8.6, High). A command injection flaw in the AP's diagnostic CLI. This one requires an authenticated administrator, so it's a much smaller worry on its own, but it turns any stolen or weak admin login into full control of the device. Reported by Carlos Garrido of Pentraze Cybersecurity.
The nuances, because getting them right is the whole point of this series:
- The two 9.3s need no credentials at all. The CVSS vectors for both record
PR:N(no privileges required),UI:N(no user interaction) andAT:N(no special conditions). That is a clean, unconditional pre-auth flaw, not a “critical” that quietly needs a login first. - But they do need network access to the AP. WatchGuard's own wording is “an unauthenticated attacker with network access to the AP.” This is not, on the face of the advisory, something a stranger on the internet can reach. It's something anyone already on your LAN can reach. Hold that thought; it's the lesson.
- Not exploited, not on CISA's list. WatchGuard says it is “not aware of any exploitation of this vulnerability in the wild,” none of the three appears on CISA's Known Exploited Vulnerabilities catalogue, and CISA's own automated triage for CVE-2026-101891 records exploitation as “none.” The same triage also records the flaw as automatable with total technical impact, which is a polite way of saying it would scan and script very nicely if someone chose to.
- The 9.3 is the vendor's number. At the time of writing, the NVD record is marked “Deferred,” meaning NVD hasn't independently re-scored it. That's not unusual in 2026, but it's worth knowing.
- Affected: “WatchGuard AP” firmware 1.0 up to (but not including) 3.4.8. Fixed in 3.4.8. That firmware line is the one WatchGuard ships for access points managed in WatchGuard Cloud: the AP130, AP230W, AP330, AP332CR, AP430CR and AP432. Firmware v3.4.8 went GA on 24 September 2026; its release notes list a couple of Wi-Fi fixes and “minor updates and bug fixes,” with the security detail arriving in the advisories four days later.
Why it matters: the box on the ceiling is a computer on your LAN
It's easy to think of an access point as a radio. It isn't. It's a small Linux computer with its own management API, and in a flat network (which describes most small-business networks we see) every device that can get an IP address can talk to it. That means “network access to the AP” includes the laptop a contractor plugged into the boardroom port, the phone that joined your guest Wi-Fi, the reception PC that opened a bad attachment last Tuesday, and the smart TV nobody has updated since it was unboxed.
Once someone owns the access point, they're sitting on the device every wireless client trusts. They can watch who's connecting, tamper with traffic, set up a look-alike network, and use the AP as a quiet, persistent foothold that no antivirus will ever see, because it isn't a PC. We wrote about this exact pattern in the Tenda backdoor piece and the forgotten-gear piece: infrastructure that nobody thinks of as a computer gets treated as furniture, and furniture doesn't get patched.
There's a second, quieter lesson in the timing. The fix shipped on 24 September with release notes that read like any other maintenance update. If you only patch when a release note says “security,” you'd have skipped this one. The safer habit is to treat every firmware release on your firewall and Wi-Fi gear as potentially security-relevant, because increasingly, that's how vendors do it: fix first, disclose once customers have had a few days' head start.
The honest bit
No vendor is immune, including the ones we like, and we hold everyone to the same standard. We said it about Cisco's own end-of-life routers, and in WatchGuard's favour we'll say this: finding the worst of these flaws yourself, shipping the fix before disclosure, crediting the external researchers, and publishing three clear advisories with exact version ranges is good handling. It is also the second WatchGuard advisory we've covered this year after the Firebox VPN flaw, and WatchGuard's Firebox line has four entries on CISA's exploited list, two of them from the past year. WatchGuard advisories are worth reading the day they land.
Cloud management genuinely helps here, and we've argued why that model keeps improving after you buy it. WatchGuard Cloud can upgrade access points automatically, stagger the reboots, and keep them inside a maintenance window. But read the fine print: the automatic option applies a grace period of 7 to 28 days after a release before it installs. Set to 28 days, your APs would still be running the vulnerable firmware in late October. Auto-update is a safety net, not a substitute for looking.
What we'd suggest you actually do
- Check the firmware version on every WatchGuard AP today and move to 3.4.8. In WatchGuard Cloud, Configure > Devices shows each access point and lets you upgrade now or at a scheduled time. The AP reboots after the upgrade, so pick a quiet hour, but pick one this week.
- Don't rely on the auto-update grace window for this one. If you've enabled scheduled automatic upgrades, that's great for the long run. For a pre-auth 9.3, push it manually and let the schedule catch the next release.
- Put your access points' management on its own VLAN. The whole risk in these flaws lives in the phrase “network access to the AP.” If guest devices, printers and staff laptops can't reach the management addresses of your Wi-Fi and switching gear, you've removed most of the attack surface for this and the next one like it.
- Isolate guest Wi-Fi properly. Client isolation on, no route to the internal LAN, and no path from a guest client to any infrastructure address. Test it with a phone rather than assuming.
- Review who holds admin on your WatchGuard Cloud account. The third flaw turns an admin login into a root shell on the AP. Remove stale accounts, use unique passwords, and turn on multi-factor authentication for every administrator.
- Count your access points. Then walk around and count them again. The one in the warehouse mezzanine that was installed for the old barcode scanners is exactly the one that's still on 2.7.
- Subscribe to your vendors' advisory feeds. WatchGuard publishes an RSS feed from its security advisories page. News like this should reach you the same day, not when it turns up in a quarterly report.
The friendly takeaway
This isn't a five-alarm fire, and we won't dress it up as one. It's a serious flaw, caught early, fixed before it was announced, with no sign of anyone using it. What makes it worth your ten minutes is the reminder underneath it: your Wi-Fi access points are computers on your network, and anything on your network can talk to them unless you've deliberately arranged otherwise. Patch the firmware this week, and use the moment to check whether your guest Wi-Fi can see your infrastructure.
As always, this post is part of us keeping watch so you don't have to. If you'd like a second pair of eyes over your Wi-Fi setup, what's patched, what's segmented, and whether that AP in the warehouse is still on the books, get in touch. No obligation, no hard sell.
References
- WatchGuard PSIRT: CVE-2026-101891, WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access
- WatchGuard PSIRT: CVE-2026-86102, WatchGuard AP Command Injection in Internal Management API Allows Command Execution
- WatchGuard PSIRT: CVE-2026-87969, WatchGuard AP Authenticated Command Injection in Diagnostic CLI
- CVE.org: canonical record for CVE-2026-101891 (CVSS v4.0 vector, CWE, CISA SSVC triage)
- NVD: CVE-2026-101891
- CISA: Known Exploited Vulnerabilities Catalog (none of the three CVEs are listed)
- WatchGuard: Access Point Firmware Releases (v3.4.8-1.B747709, 24 September 2026, all WatchGuard Cloud-managed APs)
- WatchGuard: Wi-Fi in WatchGuard Cloud Release Notes
- WatchGuard Help Center: Update Access Point Firmware (manual and automatic upgrades, grace period, maintenance windows)
- WatchGuard Security Advisories (PSIRT index and RSS feed)