ELEVATED 7 min read 29 Aug 2026

CC-4836 - WatchGuard Releases Security Updates for Critical Vulnerabilities in WatchGuard Agent Leads Today's Security Review

Threat Level: Elevated Tags: cve-2026-57909, cve-2026-57910, cwe-306, cwe-94, cve-2026-55841, cwe-138, cve-2026-53362, cwe-122, kernel, cve-2026-55830

Key findings
01
CC-4836 - WatchGuard Releases Security Updates for Critical Vulnerabilities in WatchGuard Agent
CRITICAL
Severity: Medium CVE-2026-57909 and CVE-2026-57910 could allow unauthenticated remote code execution on affected WatchGuard Agent systems CVE-2026-57909 and CVE-2026-57910 could allow unauthenticated remote code execution on affected WatchGuard Agent systems. Updated: 26 Aug 2026 .
02
Fortigate syslog message parser can be exploited to modify or delete fields from the original message.
HIGH
Fortigate syslog message parser can be exploited to modify or delete fields from the original message. CVE coverage: CVE-2026-55841.
03
Linux Kernel Unspecified Vulnerability — Kernel
HIGH
CVE-2026-53362: Linux Kernel Unspecified Vulnerability — Kernel. CVE coverage: CVE-2026-53362.
04
RestrictedPython guard hooks can be shadowed via positional-only arguments
HIGH
RestrictedPython guard hooks can be shadowed via positional-only arguments. CVE coverage: CVE-2026-55830.
05
Snipe-IT has an Improper Privilege Management issue
HIGH
Snipe-IT has an Improper Privilege Management issue. CVE coverage: CVE-2026-55843.
06
Multiple vulnerabilities in free5GC AUSF
HIGH
CVE coverage: CVE-2026-55785, CVE-2026-55784. The cited advisories disclose: uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA; authentication contexts can be overwritten by concurrent requests for the same SUPI.
07
OpenStack ironic-python-agent 1.0.0 through 11.5.0: Inclusion of Functionality from Untrusted Control Sphere
HIGH
An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image. The assigned identifier is CVE-2026-43003.
08
MapFish Print has XXE that allows reading arbitrary files of certain types
HIGH
MapFish Print has XXE that allows reading arbitrary files of certain types. CVE coverage: CVE-2026-55848.
09
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read.
HIGH
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read. CVE coverage: CVE-2026-55874.
10
klever-go: SFT add-quantity int64 overflow bypasses a finite per-nonce MaxSupp
HIGH
klever-go: SFT add-quantity int64 overflow bypasses a finite per-nonce MaxSupply. CVE coverage: CVE-2026-55764.
11
Chromium: CVE-2026-78891 Buffer overflow in WebRTC
HIGH
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. The assigned identifier is CVE-2026-78891.
12
MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/
MEDIUM
MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets. CVE coverage: CVE-2026-55855.
13
org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport).
MEDIUM
org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport). CVE coverage: CVE-2026-55860.
14
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output.
MEDIUM
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output. CVE coverage: CVE-2026-55859.
15
org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Conte
MEDIUM
org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context. CVE coverage: CVE-2026-55858.

Executive assessment

Today's brief leads with CC-4836 - WatchGuard Releases Security Updates for Critical Vulnerabilities in WatchGuard Agent. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.

Finding 01 — CC-4836 - WatchGuard Releases Security Updates for Critical Vulnerabilities in WatchGuard Agent

What changed: Severity: Medium CVE-2026-57909 and CVE-2026-57910 could allow unauthenticated remote code execution on affected WatchGuard Agent systems CVE-2026-57909 and CVE-2026-57910 could allow unauthenticated remote code execution on affected WatchGuard Agent systems. Updated: 26 Aug 2026 .

Technical evidence: CVE-2026-57909; CVSS v4.0 9.4; weakness ['CWE-306', 'CWE-94']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-57909 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: digital.nhs.uk](<https://digital.nhs.uk/cyber-alerts/2026/cc-4836>)

Finding 02 — Fortigate syslog message parser can be exploited to modify or delete fields from the original message.

What changed: Fortigate syslog message parser can be exploited to modify or delete fields from the original message. CVE coverage: CVE-2026-55841.

Technical evidence: CVE-2026-55841; CVSS v3.1 7.5; weakness ['CWE-138']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-55841 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: github.com](<https://github.com/advisories/GHSA-gqr6-r77p-c2pj>)

Finding 03 — Linux Kernel Unspecified Vulnerability — Kernel

What changed: CVE-2026-53362: Linux Kernel Unspecified Vulnerability — Kernel. CVE coverage: CVE-2026-53362.

Technical evidence: CVE-2026-53362; CVSS v3.1 7.8; weakness ['CWE-122']; technical confidence High.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: Observed in-the-wild exploitation is confirmed.

Action: Map CVE-2026-53362 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: www.cisa.gov](<https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2026-53362>)

Finding 04 — RestrictedPython guard hooks can be shadowed via positional-only arguments

What changed: RestrictedPython guard hooks can be shadowed via positional-only arguments. CVE coverage: CVE-2026-55830.

Technical evidence: CVE-2026-55830; CVSS v3.1 8.3; weakness ['CWE-184']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-55830 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-ffg3-p8fm-mjx2>)

Finding 05 — Snipe-IT has an Improper Privilege Management issue

What changed: Snipe-IT has an Improper Privilege Management issue. CVE coverage: CVE-2026-55843.

Technical evidence: CVE-2026-55843; CVSS v4.0 7; weakness ['CWE-269']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-55843 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-j5g3-42wp-gqm3>)

Finding 06 — Multiple vulnerabilities in free5GC AUSF

What changed: CVE coverage: CVE-2026-55785, CVE-2026-55784. The cited advisories disclose: uses non-constant-time authentication comparisons and logs XRES in 5G-AKA; authentication contexts can be overwritten by concurrent requests for the same SUPI.

Technical evidence: CVE-2026-55784; CVSS v3.1 7.5; weakness ['CWE-362']; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-55784 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-fp46-6vfw-gc9c>)

Finding 07 — OpenStack ironic-python-agent 1.0.0 through 11.5.0: Inclusion of Functionality from Untrusted Control Sphere

What changed: An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.

Technical evidence: CVE-2026-43003; CVSS v3.1 8; weakness ['CWE-829']; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-43003 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-43003>)

Finding 08 — MapFish Print has XXE that allows reading arbitrary files of certain types

What changed: MapFish Print has XXE that allows reading arbitrary files of certain types. CVE coverage: CVE-2026-55848.

Technical evidence: CVE-2026-55848; CVSS v3.1 8.6; weakness ['CWE-611']; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-55848 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-5v29-34h8-v68r>)

Finding 09 — SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read.

What changed: SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read. CVE coverage: CVE-2026-55874.

Technical evidence: CVE-2026-55874; CVSS v3.1 7.7; weakness ['CWE-22']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-55874 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-56wq-x3wv-3ff4>)

Finding 10 — klever-go: SFT add-quantity int64 overflow bypasses a finite per-nonce MaxSupp

What changed: klever-go: SFT add-quantity int64 overflow bypasses a finite per-nonce MaxSupply. CVE coverage: CVE-2026-55764.

Technical evidence: CVE-2026-55764; CVSS v4.0 8.7; weakness ['CWE-190']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-55764 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-mrpp-v6pg-p54x>)

Finding 11 — Chromium: CVE-2026-78891 Buffer overflow in WebRTC

What changed: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability.

Technical evidence: CVE-2026-78891; CVSS v3.1 8.8; weakness ['CWE-122']; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-78891 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: chromereleases.googleblog.com](<https://chromereleases.googleblog.com/2026>)

Finding 12 — MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/

What changed: MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets. CVE coverage: CVE-2026-55855.

Technical evidence: CVE-2026-55855; CVSS v3.1 6.5; weakness ['CWE-89', 'CWE-116']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-55855 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: github.com](<https://github.com/advisories/GHSA-g5xc-5w98-jfvm>)

Finding 13 — org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport).

What changed: org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport). CVE coverage: CVE-2026-55860.

Technical evidence: CVE-2026-55860; CVSS v3.1 5.9; weakness ['CWE-319', 'CWE-522']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-55860 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: github.com](<https://github.com/advisories/GHSA-c857-9x2m-cvh2>)

Finding 14 — org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output.

What changed: org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output. CVE coverage: CVE-2026-55859.

Technical evidence: CVE-2026-55859; CVSS v3.1 5.9; weakness ['CWE-116', 'CWE-838']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-55859 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: github.com](<https://github.com/advisories/GHSA-5rqc-86vf-g8r2>)

Finding 15 — org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Conte

What changed: org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context. CVE coverage: CVE-2026-55858.

Technical evidence: CVE-2026-55858; CVSS v3.1 5.9; weakness ['CWE-838']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-55858 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits:** exploitation status unknown

fixed version or patch state unknown

[Evidence source: github.com](<https://github.com/advisories/GHSA-xvr9-35cr-46v9>)

cve-2026-43003cve-2026-53362cve-2026-55764cve-2026-55785cve-2026-55830cve-2026-55841cve-2026-55843cve-2026-55848cve-2026-55855cve-2026-55858

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.