WatchGuard Endpoint PSKMAD auth bypass is CVE-2026-13043
WatchGuard Endpoint Security for Windows before protection 8.00.26.0012 has a missing authentication flaw in its PSKMAD kernel memory driver. A local user can forge the driver's access handshake and disclose kernel and process memory. CVSS 4.0 9.3 (WatchGuard). Fixed in 8.00.26.0012. Public PoC exists. Not in CISA KEV.
Published 10 Oct 2026
What happened
On 1 October 2026 WatchGuard published CVE-2026-13043 for its Endpoint Security product on Windows. WatchGuard is the CNA. The flaw sits in the Kernel Memory Access Driver, also called PSKMAD. The on-disk name is pskmad.sys. It is a Panda Security component that WatchGuard still ships after acquiring Panda.
The driver is meant to let the antivirus engine inspect memory from the kernel. Callers are supposed to pass an access-control handshake before they can use those privileged functions. WatchGuard says a local, authenticated attacker can bypass that handshake and send privileged commands to the driver. The result is disclosure of kernel and process memory.
WatchGuard scores the issue CVSS 4.0 9.3 (Critical). It maps the weakness to CWE-306 and CWE-798. NVD lists the same WatchGuard score and marks the record Undergoing Analysis. There is no separate NVD base score.
WatchGuard Endpoint Security Prime release notes, dated 1 October 2026 for Windows protection 8.00.26.0012, say that build resolves the CVE. The notes describe the impact as reading memory allocated to other processes through specially crafted requests.
Who is affected
The CVE record and the PSIRT page both scope the issue to WatchGuard Endpoint Security on Windows, versions before protection 8.00.26.0012. Builds at 8.00.26.0012 and later are not affected.
macOS and Linux Endpoint Security lines are outside the advisory. Canada's cyber centre alert AV26-990, published 2 October 2026, repeats the same Windows product and version range.
WatchGuard does not publish a separate matrix of brand names such as EPDR or Adaptive Defense for this CVE. Operators should inventory any Windows host that still runs WatchGuard or Panda endpoint protection and check the Windows protection version.
A second exposure path exists when the signed driver is present even without a full product install. Researchers and the LOLDrivers catalog treat a copy of this driver as usable in a bring-your-own-vulnerable-driver (BYOVD) scenario: an attacker with enough local rights loads the signed binary and then abuses it. That path is outside WatchGuard's product version table, but it matters for hosts that never had the product installed.
What is confirmed
WatchGuard confirms missing authentication in PSKMAD, local authenticated access as the attack path, memory disclosure as the impact, and the fixed protection build 8.00.26.0012. CISA's SSVC entry for the CVE sets exploitation to none. The CVE is not in the CISA KEV catalog. Canada's AV26-990 likewise does not report exploitation in the wild.
GitHub user TheMalwareGuardian (Alejandro Vázquez Vázquez) published a public repository for CVE-2026-13043 on 7 October 2026. The README claims a BYOVD chain: load the signed driver, forge the handshake, then demonstrate privileged reads of process memory and related kernel-visible state. It credits Juan Sacco of Exploit Pack with discovery and points to earlier LOLDrivers work by Xusheng Li on the same driver sample. ThreatWire did not run it. Availability is therefore PoC.
The publisher's account has existed since 2022 and hosts many CVE-titled research repositories, mostly about UEFI and Windows internals. The CVE number on this repo matches the WatchGuard advisory. ThreatWire treats those points as packaging context, not as proof of malware. This article does not reprint handshake values, request codes, or steps.
LOLDrivers lists the driver sample (file version 1.1.0.23) as vulnerable and verified. It notes that the device grants access to administrators and LocalSystem, and that this is not a standard-user entry point. That privilege nuance sits alongside WatchGuard's CVSS vector, which sets privileges required to Low.
What is not confirmed
Exploitation in ransomware or EDR-killer campaigns is not confirmed by WatchGuard, CISA, or Canada's cyber centre. No vendor advisory names EPDR, EDR, EPP, or Adaptive Defense as separate SKUs for this CVE; those labels should not be assumed without inventory evidence.
ThreatWire did not verify the PoC beyond public repository metadata and README prose. Claims about defeating specific Windows mitigations, or about which older driver versions share the same handshake flaw, come from researcher write-ups rather than from WatchGuard. Earlier Panda driver CVEs from 2023 (CVE-2023-6330 and related) are separate issues on older file versions.
What to do
Update WatchGuard Endpoint Security on Windows to protection 8.00.26.0012 or later. Confirm the protection version in the management console or on the endpoint, not only the agent version. WatchGuard rolls out Endpoint Security updates gradually; if the console shows no upgrade alert, contact WatchGuard to request the build.
Until every Windows host is on a fixed protection build, restrict local administrator rights. Prefer application control or Microsoft's vulnerable-driver blocklist to stop unexpected loading of pskmad.sys where the product is not required. Hunt for the known vulnerable sample hash published by LOLDrivers if your tooling supports driver inventory.
If you suspect abuse, collect evidence of unexpected service creation for the driver and of local tools talking to its device interface, then rotate credentials that may have been present in process memory.
Sources: WatchGuard PSIRT CVE-2026-13043, WatchGuard Endpoint Security Prime release notes, Canadian Centre for Cyber Security AV26-990, NVD and CVE.org, GHSA-33g3-qcrh-xvc2, LOLDrivers, and the public PoC repository metadata.