Vulnerabilities · 2 days ago

WatchGuard Driver Bug Exposes Kernel Memory

WatchGuard disclosed a critical flaw in Endpoint Security for Windows, tracked as CVE-2026-13043, that affects versions before 8.00.26.0012. INCIBE-CERT says a local authenticated attacker could abuse the kernel memory access driver to read kernel and other-process memory.

The bug is an authentication bypass in the protection driver: the driver is supposed to check whether a caller is allowed to issue privileged commands, but the flaw lets a logged-in user skip that gate and ask for memory it should not reveal. That can leak system internals, credentials, or other sensitive data already resident on the endpoint.

For Windows fleets that rely on WatchGuard’s kernel driver as part of endpoint protection, the trust boundary is the driver itself, not just the surrounding app. A local foothold on an affected machine can become a memory-disclosure problem even without a broader compromise.

CVE-2026-13043

NVD KEV

Timeline

Sources

2 sources covering this story

Entities

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-10-05

Editions

Related stories