← All CVEs

CVE-2026-86102

critical · 9.3

An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.

9.3
CVSS
—
EPSS (exploit prob.)
—
EPSS percentile
2026-09-28
Published

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Weaknesses

CWE-78CWE-863

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-86102