CVE-2026-57909
A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary cod
CVSS
—
No CVSS
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Published: Aug 25, 2026 · Last modified: Aug 28, 2026 · CWE-94 · CWE-306
0.3%EPSS · 30 days0.3%
2026-08-262026-09-06
A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-19397——
———Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session.
Refer to the '
Security Update for ASUS Control Center Express Agent ' section on the ASUS Security Advisory for more information.8hCVE-2026-865439.8 CRI—
———knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.12hCVE-2026-865065.9 MED—
———In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data18hCVE-2026-865028.4 HIG—
———In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts18hCVE-2026-864863.7 LOW—
———In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank18hCVE-2026-864809.8 CRI—
———In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges18h