Vulnerabilities & Exploits

WatchGuard Driver Bug Exposes Kernel Memory

WatchGuard disclosed a critical flaw in Endpoint Security for Windows, tracked as CVE-2026-13043, that affects versions before 8.00.26.0012. INCIBE-CERT says a local authenticated attacker could abuse the kernel memory access driver to read kernel and other-process memory.

The bug is an authentication bypass in the protection driver: the driver is supposed to check whether a caller is allowed to issue privileged commands, but the flaw lets a logged-in user skip that gate and ask for memory it should not reveal. That can leak system internals, credentials, or other sensitive data already resident on the endpoint.

For Windows fleets that rely on WatchGuard’s kernel driver as part of endpoint protection, the trust boundary is the driver itself, not just the surrounding app. A local foothold on an affected machine can become a memory-disclosure problem even without a broader compromise.

2 sources · 2 days ago

CVE-2026-13043

NVD KEV

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-10-05

Every edition of this story: WatchGuard Driver Bug Exposes Kernel Memory

More from today