Vulnerabilities · 2 days ago
WatchGuard disclosed a critical flaw in Endpoint Security for Windows, tracked as CVE-2026-13043, that affects versions before 8.00.26.0012. INCIBE-CERT says a local authenticated attacker could abuse the kernel memory access driver to read kernel and other-process memory.
The bug is an authentication bypass in the protection driver: the driver is supposed to check whether a caller is allowed to issue privileged commands, but the flaw lets a logged-in user skip that gate and ask for memory it should not reveal. That can leak system internals, credentials, or other sensitive data already resident on the endpoint.
For Windows fleets that rely on WatchGuard’s kernel driver as part of endpoint protection, the trust boundary is the driver itself, not just the surrounding app. A local foothold on an affected machine can become a memory-disclosure problem even without a broader compromise.
2 sources covering this story
Risolta vulnerabilità in WatchGuard Endpoint Security
WatchGuard ha rilasciato aggiornamenti di sicurezza per sanare una vulnerabilità con gravità "critica" in Endpoint Security per Windows, soluzione dedicata alla protezione dei dispositivi terminali.
Ausencia de autenticación en Endpoint Security de WatchGuard
WatchGuard ha publicado una vulnerabilidad de severidad crítica que, en caso de ser explotada, podría
Part of the PlainSec briefing for 2026-10-05