CVE-2026-13043
WatchGuard Endpoint Security PSKMAD missing authentication
WatchGuard Endpoint Security for Windows before protection 8.00.26.0012 ships a Kernel Memory Access Driver (PSKMAD) that does not properly authenticate callers. A local, authenticated attacker can bypass the driver's access-control handshake and send privileged commands that disclose kernel and process memory. CVSS 4.0 9.3 (WatchGuard). Public PoC exists. Not in CISA KEV.
- CVSS
- 9.3
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- Class
- Info disclosure
- Status
- PoC Available
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- WatchGuard
- Products
- WatchGuard Endpoint Security (Windows)
- Affected
- WatchGuard Endpoint Security for Windows, protection versions before 8.00.26.0012, per the WatchGuard PSIRT advisory and CVE record.
- Fixed
- Windows protection 8.00.26.0012 and later. WatchGuard Endpoint Security Prime release notes date that protection build to 1 October 2026.
- Published
- 1 Oct 2026
- Updated
- 10 Oct 2026
The status above is the claim. Links do not upgrade it.
CVE-2026-13043 is a missing authentication flaw in the Kernel Memory Access Driver (PSKMAD) shipped with WatchGuard Endpoint Security for Windows. WatchGuard is the CNA. The driver is the Panda Security component pskmad.sys, still used after WatchGuard acquired Panda. It is meant to let the endpoint product inspect memory from the kernel. Access is supposed to require a handshake that only trusted product components can complete.
The handshake can be forged by a local, authenticated attacker. Once past it, the attacker can send privileged commands to the driver and obtain disclosure of kernel and process memory. WatchGuard maps the issue to CWE-306 (missing authentication for a critical function) and CWE-798 (use of hard-coded credentials).
WatchGuard scores it CVSS 4.0 9.3 (Critical). NVD lists the same WatchGuard score and marks the record Undergoing Analysis. There is no separate NVD score. Affected versions are all Windows Endpoint Security builds before protection 8.00.26.0012. Fixed builds are 8.00.26.0012 and later. WatchGuard Endpoint Security Prime release notes, dated 1 October 2026 for that protection build, say the fix stops specially crafted requests that read memory belonging to other processes.
The platform scope in the CVE record is Windows only. macOS and Linux Endpoint Security lines are outside the advisory. CISA's SSVC entry sets exploitation to none. The CVE is not in the CISA KEV catalog. Canada's cyber centre published alert AV26-990 on 2 October 2026 and likewise did not report exploitation.
GitHub user TheMalwareGuardian (Alejandro Vázquez Vázquez) published a public repository for CVE-2026-13043 on 7 October 2026. The README frames the issue as a bring-your-own-vulnerable-driver (BYOVD) case: a signed copy of the driver can be loaded and then abused for process memory reads and related privileged reads. It credits Juan Sacco of Exploit Pack with discovery and cites earlier LOLDrivers work by Xusheng Li. ThreatWire did not run the project. Availability is therefore PoC. This record does not reprint handshake values, request codes, or steps.