Threat reportVulnerabilityTL-2026-3315

CVE-2026-13043: WatchGuard/Panda Kernel Memory Access Driver (pskmad.sys) Missing Authentication Exposes Kernel and Process Memory

criticalMONITORING

CVE-2026-13043 (TL-2026-3315), also tracked as PSKMAD missing authentication, is a critical-severity software vulnerability scored CVSS 9.3, first published 2026-10-11. It has no confirmed attribution, affects WatchGuard WatchGuard Endpoint Security for Windows (Panda Kernel, references 1 CVE (CVE-2026-13043), maps to 5 MITRE ATT&CK techniques (T1003.001, T1005, T1057), and is covered by 9 detection rules and 10 indicators of compromise.

CVSS
9.3/10Critical
CVEs
1Referenced vulnerabilities
Techniques
5MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
10Indicators of compromise

Key facts for TL-2026-3315

Threat ID
TL-2026-3315
Also known as
PSKMAD missing authentication, pskmad.sys PsOpenPacket000 handshake bypass
Severity
CRITICAL
CVSS
9.3 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
Status
MONITORING
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, enterprise, government administration, finance
Target regions
Global
Detection rules
9
Indicators of compromise
10

How CVE-2026-13043 works

A missing-authentication flaw (CWE-306) in the Panda Kernel Memory Access Driver (pskmad.sys, device \\.\PSMEMDriver) shipped with WatchGuard Endpoint Security for Windows lets a local user bypass the driver's PsOpenPacket000 handshake and issue privileged commands, disclosing kernel and process memory. A public PoC reportedly dumps LSASS on Windows 11 25H2 with VBS/HVCI/kCET enabled. Fixed in 8.00.26.0012.

CVE-2026-13043 (CVSS v4.0 9.3, vector CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H) is a missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD, pskmad.sys) used by WatchGuard endpoint security products, inherited from Panda Security. The driver exposes a user-mode interface through the device \\.\PSMEMDriver (\Device\PSMEMDriver, \Global??\PSMEMDriver). According to the CNA description, a local, authenticated attacker can bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process memory. Weaknesses recorded against the CVE are CWE-306 (Missing Authentication for Critical Function) and CWE-798 (Use of Hard-coded Credentials); the advisory also maps CAPEC-115 (Authentication Bypass) and CAPEC-194 (Fake the Source of Data).

Per the researcher's write-up (Juan Sacco, exploitpack.com) and the GBHackers coverage, the driver translates user-controlled requests into privileged kernel operations without authenticating the caller. The handshake is an extended-attribute packet named PsOpenPacket000 combined with named synchronization objects (Global\DOGPskMadSec_*, Global\DOGPskMadSignal_*, Global\DOGPskMadReply_*); the magic value is withheld by the researcher. Once bypassed, the IOCTL interface (METHOD_BUFFERED, FILE_ANY_ACCESS, device type 0xB370) exposes four operations: TRANSFER (0xB3702C08), ENTRY_MAP (0xB3702C0C), ENTRY_UNMAP (0xB3702C10) and MSR access (0xB3702C3C). The PoC reads the IA32_LSTAR MSR (0xC0000082, the system call entry point) to defeat kASLR, enumerates the target process virtual-address mappings, and dumps process memory, including LSASS (PID 1020 in the demo), by supplying a target process identifier and virtual address and reading page-sized chunks across committed, readable regions. It is reported to work on fully patched Windows 11 25H2 with VBS, HVCI and kCET enabled, because the read primitive is provided by a legitimately signed vendor driver rather than by a kernel exploit. Memory exposure includes credentials, authentication tokens, session data, private keys, browser data and application secrets.

The analyzed driver sample is pskmad.sys x64, file version 1.1.0.23 (product 1.1.0.45), 63,360 bytes, SHA-256 9bf3b737afa4d4f5e7b00ec749d4b75656ad66d9a2b402e1e81934e95ba7df5b, signed via the Microsoft Windows Hardware Compatibility Publisher, company Panda Security, S.L.U. The vendor PSIRT advisory (published 2026-10-01) lists WatchGuard Endpoint Security for Windows versions prior to 8.00.26.0012 as affected, 8.00.26.0012 as the fixed release, and no documented workaround; no credits are listed in the advisory. The vulnerability requires local code execution or a local authenticated session; no network exploitation is possible.

Exploitation status: GBHackers dates the advisory 2026-10-05 and its article 2026-10-06; the hunt feed described active exploitation, but the article text does not explicitly confirm it, a secondary analysis (Ayi NEDJIMI Consultants, updated 2026-10-11) states no in-the-wild exploitation was confirmed, and the CVE is not listed in CISA KEV as of the sources reviewed. No network IOCs (no IPs/domains, so no BeaconBeagle correlation applicable), no threat-actor attribution and no malware families are published. The pskmad_64.sys driver has been the subject of earlier WatchGuard PSIRT advisories (WGSA-2024-00001, -00002, -00003: pool memory corruption, out-of-bounds write, arbitrary memory read), and the researcher cites older Panda-lineage issues (CVE-2015-1438, CVE-2017-8339, CVE-2023-6330/6331/6332), indicating a recurring weak driver attack surface.

Defensive relevance: a signed security-vendor driver with an unauthenticated read primitive is a bring-your-own-vulnerable-driver (BYOVD)-style credential-theft enabler that bypasses VBS/HVCI protections for user-mode secrets. Defenders should patch to 8.00.26.0012, monitor handles/opens to PSMEMDriver from unexpected processes, watch for LSASS access by non-security tooling, and consider blocking the vulnerable driver hash after compatibility testing.

MITRE ATT&CK techniques used in TL-2026-3315

Credential Access

T1003.001 LSASS Memory; T1212 Exploitation for Credential Access

Collection

T1005 Data from Local System

Discovery

T1057 Process Discovery

Execution

T1106 Native API

Affected products and versions in CVE-2026-13043

  • WatchGuard — WatchGuard Endpoint Security for Windows (Panda Kernel Memory Access Driver, pskmad.sys)
    Vulnerable versions: all versions prior to 8.00.26.0012
    Fixed in: 8.00.26.0012

Remediation for CVE-2026-13043

Patches

  • WatchGuard Endpoint Security for Windows 8.00.26.0012

Immediate actions

  • Update WatchGuard Endpoint Security for Windows to 8.00.26.0012 or later via the centralized management console
  • Verify agent version compliance through agent version reporting
  • Monitor for unexpected access to the PSMEMDriver device from non-vendor processes
  • Hunt for the vulnerable pskmad.sys SHA-256 and for creation of Global\DOGPskMad* named objects by non-WatchGuard processes

Workarounds

  • No vendor workaround documented; restrict device access and enforce least-privilege local accounts until patched

Longer-term hardening

  • Enable Windows vulnerable driver blocklist / WDAC driver block rules and block the vulnerable pskmad.sys after compatibility testing
  • Enable LSA protection (RunAsPPL) and Credential Guard and alert on LSASS access
  • Enforce least-privilege for local accounts to limit who can open privileged driver devices

CVEs associated with CVE-2026-13043

CVE-2026-13043

Weaknesses (CWE) in CVE-2026-13043

CWE-306, CWE-798

Timeline of CVE-2026-13043

  • Earlier Panda-lineage driver issues (CVE-2023-6330/6331/6332) cited by the researcher; WatchGuard later published WGSA-2024-00001/2/3 for pskmad_64.sys (pool corruption, OOB write, arbitrary memory read), showing a recurring weak driver surface.
  • CVE-2026-13043 published and WatchGuard PSIRT advisory released: WatchGuard Endpoint Security for Windows before 8.00.26.0012 affected; fixed in 8.00.26.0012; no workaround.
  • Juan Sacco publishes research on exploitpack.com detailing the PsOpenPacket000 handshake bypass, IOCTL operations and LSASS dump PoC; GBHackers dates the advisory to this day.
  • Hunt feed reported active exploitation; the article text does not explicitly confirm it and no in-the-wild exploitation or CISA KEV listing was found in other sources.
  • GBHackers publishes details of the PoC: memory transfer/mapping/unmapping/MSR operations, IA32_LSTAR read and LSASS dump (PID 1020) on Windows 11 25H2 with VBS/HVCI/kCET.
  • Secondary analysis (Ayi NEDJIMI Consultants) updated: affected range prior to 8.00.26.0012, no confirmed in-the-wild exploitation, not in CISA KEV.

Sources cited for CVE-2026-13043

Detection coverage for TL-2026-3315

As of 2026-10-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3315 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
10 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats