WatchGuard Endpoint Security flaw CVE-2026-13043 gives unauthenticated access to kernel memory: update agents to 8.00.26.0012
EditorialBy TrustList Editorial
WatchGuard published CVE-2026-13043, rated 9.3, on 1 October 2026: a kernel-memory driver in WatchGuard Endpoint Security lacks authentication, allowing arbitrary kernel memory access. Every version before 8.00.26.0012 is affected.
- Cybersecurity
- Vulnerability Management
- Patch Management
- Endpoint Management
About WatchGuard Endpoint Security flaw CVE-2026-13043 gives unauthenticated access to kernel memory: update agents to 8.00.26.0012
WatchGuard Endpoint Security flaw CVE-2026-13043 gives unauthenticated access to kernel memory: update agents to 8.00.26.0012
2 October 2026 — WatchGuard published a critical vulnerability in WatchGuard Endpoint Security, its endpoint protection and detection product line (the former Panda Security products), on 1 October 2026. CVE-2026-13043 is rated 9.3. WatchGuard describes it as "Missing Authentication in Kernel Memory Access Driver Allows Arbitrary Kernel Memory Access". The Canadian Centre for Cyber Security issued an advisory on it on 2 October.
Not yet independently verified. This rests on WatchGuard’s own advisory list and the Canadian Centre’s advisory; WatchGuard gives no further technical detail, and no exploitation has been reported. We will update this when it can be confirmed, and remove this note.
What is affected
- Product: WatchGuard Endpoint Security agents.
- Versions: every version before 8.00.26.0012.
- Fixed: 8.00.26.0012 and later.
Why it matters
Security agents run with the highest privileges on every laptop and server they protect. A driver that lets unauthenticated code read and write kernel memory is exactly what attackers look for to switch off security tools or gain full control of a machine: vulnerable signed drivers from security and hardware vendors have repeatedly been abused in "bring your own vulnerable driver" attacks by ransomware groups. The flaw turns the protection itself into a route in.
What to do
- Check the agent version across your fleet in the WatchGuard management console and update every endpoint to 8.00.26.0012 or later.
- Look for endpoints that missed automatic updates: machines offline for long periods, servers excluded from update rings, and golden images used to build new machines.
- Add the vulnerable driver versions to your driver block list where your tooling allows, so an attacker cannot reinstall an old copy.
- If a managed security provider runs your endpoint security, ask when the fleet was updated.
Sources
Categories & features
- Cybersecurity
- Vulnerability Management
- Patch Management
- Endpoint Management
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.