---
cve: "CVE-2026-86102"
severity: "CRITICAL"
cvss: 9.3
epss: "1.8%"
vendor: "WatchGuard"
kev: false
exploited: false
published: "2026-09-28 17:17:51"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-10-01T18:52:59+02:00"
---

# CVE-2026-86102

> 9.3 CRITICAL

## Beschreibung

An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.

## CNA-Record (Kanon, cvelistV5)

- CNA: **WatchGuard**
- State: PUBLISHED
- Stand: 2026-09-28 18:02:56
- CNA-CVSS: **9.3** (`CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **yes**
  - Technical Impact: **total**

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://psirt.watchguard.com/CVE-2026-86102>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-86102) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
