VYPR

Agent

by WatchGuard

CVEs (9)

  • CVE-2026-57909CriAug 25, 2026
    risk 0.61cvss —epss 0.00

    A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.

  • CVE-2026-57910CriAug 25, 2026
    risk 0.60cvss —epss 0.00

    Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.

  • CVE-2026-6788HigMay 6, 2026
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows allows Using Malicious Files.

  • CVE-2026-6787HigMay 6, 2026
    risk 0.51cvss 7.8epss 0.00

    Use of Hard-coded Cryptographic Key vulnerability in WatchGuard Agent on Windows allows Inclusion of Code in Existing Process.

  • CVE-2026-41288HigMay 6, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allows an authenticated local user to elevate their privileges to NT AUTHORITY\\SYSTEM.

  • CVE-2024-6594HigSep 25, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker with network access to the client could create a denial of service condition for the Single…

  • CVE-2026-41286MedMay 6, 2026
    risk 0.42cvss 6.5epss 0.00

    Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local network could exploit this vulnerability to crash the agent service.

  • CVE-2026-41287MedMay 6, 2026
    risk 0.42cvss 6.5epss 0.00

    Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local network could exploit this vulnerability to crash the agent service.

  • CVE-2005-1214Jun 14, 2005
    risk 0.01cvss —epss 0.13

    Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.