Free delivery

GGuestNot signed in
You're not signed in
LoginCreate account

9/27/2026 • Security

WatchGuard AuthPoint Gateway: When the First Factor Fails Open

WatchGuard has patched CVE-2026-95676, a flaw that lets an attacker slip past the password check in AuthPoint Gateway's LDAP Sync. The second factor still holds — which is exactly the point worth taking away from it.

On 23 September 2026, WatchGuard published an advisory about a flaw in its own multi-factor authentication product — and the most useful thing about it is what it doesn't say. CVE-2026-95676 is an improper-authentication bug in the AuthPoint Gateway, the piece of software that sits on a server inside your network and connects WatchGuard's cloud MFA service to your Active Directory. Under certain non-default conditions, an attacker can get past the password check without knowing the password. What they still can't get past is the second factor. Nobody has been attacked through it, a fix already exists, and the honest headline is "patch it this month, don't panic" — which is a result worth understanding rather than skimming.

What happened, in plain English

If you use AuthPoint, most of it lives in WatchGuard Cloud — but not all of it. The AuthPoint Gateway is an application you install on a Windows server on your own network so AuthPoint can talk to your RADIUS clients, the AD FS agent, and your Active Directory or LDAP database. It runs as four services (Gateway, RADIUS, LDAP and ADFS) and acts as a RADIUS server for things like VPN logins. Part of its job is LDAP Sync: AuthPoint's LDAP external identities pull user accounts out of your directory and, crucially, validate those users' passwords against it.

That password validation is the first factor. CVE-2026-95676 is a fault in it. WatchGuard's wording is precise and worth reading closely: the flaw "allows a remote attacker to bypass single-factor password verification under non-default operating conditions", and — the sentence that changes the whole shape of the story — "additional authentication factors still apply."

So, the nuances, because getting them right is the whole job here:

  • This is not a full MFA bypass. It defeats the password step, not the push approval or one-time code behind it. Anyone reporting this as "WatchGuard MFA bypassed" has overshot the advisory.
  • The severity is genuine but not apocalyptic. WatchGuard rates it 7.4 (High) on CVSS v4.0, vector AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N. No credentials are needed (PR:N), but the vector also records that exploitation depends on a targeted user taking some action (UI:A) and on deployment-specific conditions being present (AT:P) — consistent with the "non-default operating conditions" caveat. Worth noting that as of this writing the NVD record is still "Awaiting Analysis", so 7.4 is the vendor's own score, not an independently reassessed one.
  • It is not being exploited. WatchGuard says it is "not aware of any exploitation of this vulnerability in the wild," it is not on CISA's Known Exploited Vulnerabilities list, and CISA's own automated assessment records exploitation as "none" and the flaw as not automatable. It was found internally by WatchGuard, not by an incident.
  • It only matters if you sync from LDAP. WatchGuard notes the vulnerability "affects deployments that are configured to sync AuthPoint users from an LDAP source."
  • Affected versions are wide: AuthPoint Authentication Gateway 4.2.2 up to (but not including) 7.5.1. The fix is 7.5.1.

One more detail is quietly instructive. WatchGuard tagged this with two weaknesses: CWE-287 (Improper Authentication) and CWE-636, "Not Failing Securely" — better known as failing open. When something went sideways in the password check, the answer came back yes instead of no. Every system you run makes that choice somewhere.

Why it matters: this is what the second factor is for

We've spent a lot of this series on maximum-severity, actively-exploited flaws — the Cisco ISE zero-day, the SonicWall SMA1000 pair where the patch arrived after the attack. Those are the ones that make headlines. This one is the opposite shape, and it's arguably more useful to think about.

A layer failed. Not a minor layer either — the password check on an identity system. And the practical consequence was contained, because there was a second, independent layer sitting behind it that didn't fail at the same time. That is not luck. That is the entire design intent of multi-factor authentication finally being cashed in, in public, in a vendor advisory.

It's a good moment to ask the uncomfortable version of the question about your own environment: if one of my controls failed open tomorrow, what is the next thing standing there? For staff logins, the honest answer for a lot of Australian small businesses is "nothing" — the password is the only gate. This advisory is a fairly compelling argument for changing that, and it costs nothing to act on.

There's a second lesson hiding in the architecture. AuthPoint is a cloud service, but the Gateway is your Windows server, your install, your patch. Cloud-managed platforms genuinely do take patching off your plate for the things they manage — we've written about why that model keeps improving after you buy it — but almost every cloud security product ships a little on-premises connector like this one: a directory sync agent, an AD FS agent, a RADIUS proxy. Those are yours to look after, and they're precisely the kind of thing that gets installed once and then quietly forgotten in a comms cupboard.

The honest bit

No vendor is immune, including the ones we like, and we apply the same standard to everyone — we said it about Cisco's own end-of-life RV routers, and we'll say it here in WatchGuard's favour. Finding this yourself, publishing a clear advisory with an exact affected range, naming the fail-open weakness class honestly, stating plainly that other factors still apply, and shipping the fix on the day you disclose — that's close to the ideal handling of a security bug. Overstating this one would be the easy, attention-grabbing move; it would also be wrong.

That said, "handled well" doesn't mean "ignorable." WatchGuard's Firebox appliances have had two separate flaws added to CISA's exploited-vulnerabilities catalogue in the past year, one of them linked to known ransomware activity. This vendor's advisories are worth reading when they land.

What we'd suggest you actually do

  1. Check your Gateway version and update to 7.5.1. In WatchGuard Cloud, the Gateway page shows a tile per Gateway with the installed version, IP address and status. Anything from 4.2.2 up to 7.5.0 is in scope.
  2. Don't let "not exploited" become "not patched." This is the cheap kind of fix — a known flaw, a fix in hand, no attacker pressure yet, and no forensic clean-up afterwards. It's the least stressful patch you'll apply all quarter. Do it while it's still boring.
  3. Verify your second factor is genuinely enforced everywhere. It's the layer that contained this, so it's worth confirming it actually covers every resource — VPN, admin logins, remote access — with no lingering bypass groups or "temporary" exceptions from a migration two years ago.
  4. Inventory the on-prem connectors behind your cloud services. Directory sync agents, RADIUS proxies, AD FS agents, backup agents. Write down what's installed, on which server, and who patches it. You can't update what nobody remembers owning.
  5. Treat the Gateway's host as an identity server, not a general-purpose box. Restrict who can log into it, keep the OS and its Java runtime current, and don't expose it to the internet. A directory-connected server deserves the same care as a domain controller.
  6. Subscribe to your vendors' security advisories. WatchGuard publishes an RSS feed. News like this should reach you the day it lands, not the month after.

The friendly takeaway

This isn't a crisis, and we're not going to dress it up as one. It's a well-handled flaw in a product doing an important job, with a fix ready and no evidence of anyone using it. What makes it worth your time is the shape of it: a layer failed open, and the layer behind it held. If your own logins don't have a layer behind them yet, let this be the nudge.

As always, this post is part of us keeping watch so you don't have to. If you'd like a second pair of eyes over your authentication setup — what's patched, what's enforced, which quiet little agent on a server nobody's updated since 2023 — get in touch. No obligation, no hard sell.

References

Contact Us

Email: [email protected]

Phone: 1300 989 334

About

Your one-stop technology hub for all your networking, security, and IT needs. From cutting-edge networking solutions to robust security products, we provide everything your business requires to stay connected, secure, and efficient. Whether you're looking for advanced hardware, software, or services, we offer reliable, innovative technology tailored to help you build and protect your digital infrastructure.

Copyright © 2026 TYONLINE TECHNOLOGY PTY. LTD. All Rights Reserved.