Threat reportVulnerabilityTL-2026-3315
CVE-2026-13043: WatchGuard/Panda Kernel Memory Access Driver (pskmad.sys) Missing Authentication Exposes Kernel and Process Memory
CVE-2026-13043 (TL-2026-3315), also tracked as PSKMAD missing authentication, is a critical-severity software vulnerability scored CVSS 9.3, first published 2026-10-11. It has no confirmed attribution, affects WatchGuard WatchGuard Endpoint Security for Windows (Panda Kernel, references 1 CVE (CVE-2026-13043), maps to 5 MITRE ATT&CK techniques (T1003.001, T1005, T1057), and is covered by 9 detection rules and 10 indicators of compromise.
- CVSS
- 9.3/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 5MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 10Indicators of compromise
Key facts for TL-2026-3315
- Threat ID
- TL-2026-3315
- Also known as
- PSKMAD missing authentication, pskmad.sys PsOpenPacket000 handshake bypass
- Severity
- CRITICAL
- CVSS
- 9.3 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- Status
- MONITORING
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, enterprise, government administration, finance
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 10
How CVE-2026-13043 works
A missing-authentication flaw (CWE-306) in the Panda Kernel Memory Access Driver (pskmad.sys, device \\.\PSMEMDriver) shipped with WatchGuard Endpoint Security for Windows lets a local user bypass the driver's PsOpenPacket000 handshake and issue privileged commands, disclosing kernel and process memory. A public PoC reportedly dumps LSASS on Windows 11 25H2 with VBS/HVCI/kCET enabled. Fixed in 8.00.26.0012.
CVE-2026-13043 (CVSS v4.0 9.3, vector CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H) is a missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD, pskmad.sys) used by WatchGuard endpoint security products, inherited from Panda Security. The driver exposes a user-mode interface through the device \\.\PSMEMDriver (\Device\PSMEMDriver, \Global??\PSMEMDriver). According to the CNA description, a local, authenticated attacker can bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process memory. Weaknesses recorded against the CVE are CWE-306 (Missing Authentication for Critical Function) and CWE-798 (Use of Hard-coded Credentials); the advisory also maps CAPEC-115 (Authentication Bypass) and CAPEC-194 (Fake the Source of Data).
Per the researcher's write-up (Juan Sacco, exploitpack.com) and the GBHackers coverage, the driver translates user-controlled requests into privileged kernel operations without authenticating the caller. The handshake is an extended-attribute packet named PsOpenPacket000 combined with named synchronization objects (Global\DOGPskMadSec_*, Global\DOGPskMadSignal_*, Global\DOGPskMadReply_*); the magic value is withheld by the researcher. Once bypassed, the IOCTL interface (METHOD_BUFFERED, FILE_ANY_ACCESS, device type 0xB370) exposes four operations: TRANSFER (0xB3702C08), ENTRY_MAP (0xB3702C0C), ENTRY_UNMAP (0xB3702C10) and MSR access (0xB3702C3C). The PoC reads the IA32_LSTAR MSR (0xC0000082, the system call entry point) to defeat kASLR, enumerates the target process virtual-address mappings, and dumps process memory, including LSASS (PID 1020 in the demo), by supplying a target process identifier and virtual address and reading page-sized chunks across committed, readable regions. It is reported to work on fully patched Windows 11 25H2 with VBS, HVCI and kCET enabled, because the read primitive is provided by a legitimately signed vendor driver rather than by a kernel exploit. Memory exposure includes credentials, authentication tokens, session data, private keys, browser data and application secrets.
The analyzed driver sample is pskmad.sys x64, file version 1.1.0.23 (product 1.1.0.45), 63,360 bytes, SHA-256 9bf3b737afa4d4f5e7b00ec749d4b75656ad66d9a2b402e1e81934e95ba7df5b, signed via the Microsoft Windows Hardware Compatibility Publisher, company Panda Security, S.L.U. The vendor PSIRT advisory (published 2026-10-01) lists WatchGuard Endpoint Security for Windows versions prior to 8.00.26.0012 as affected, 8.00.26.0012 as the fixed release, and no documented workaround; no credits are listed in the advisory. The vulnerability requires local code execution or a local authenticated session; no network exploitation is possible.
Exploitation status: GBHackers dates the advisory 2026-10-05 and its article 2026-10-06; the hunt feed described active exploitation, but the article text does not explicitly confirm it, a secondary analysis (Ayi NEDJIMI Consultants, updated 2026-10-11) states no in-the-wild exploitation was confirmed, and the CVE is not listed in CISA KEV as of the sources reviewed. No network IOCs (no IPs/domains, so no BeaconBeagle correlation applicable), no threat-actor attribution and no malware families are published. The pskmad_64.sys driver has been the subject of earlier WatchGuard PSIRT advisories (WGSA-2024-00001, -00002, -00003: pool memory corruption, out-of-bounds write, arbitrary memory read), and the researcher cites older Panda-lineage issues (CVE-2015-1438, CVE-2017-8339, CVE-2023-6330/6331/6332), indicating a recurring weak driver attack surface.
Defensive relevance: a signed security-vendor driver with an unauthenticated read primitive is a bring-your-own-vulnerable-driver (BYOVD)-style credential-theft enabler that bypasses VBS/HVCI protections for user-mode secrets. Defenders should patch to 8.00.26.0012, monitor handles/opens to PSMEMDriver from unexpected processes, watch for LSASS access by non-security tooling, and consider blocking the vulnerable driver hash after compatibility testing.
MITRE ATT&CK techniques used in TL-2026-3315
Credential Access
T1003.001 LSASS Memory; T1212 Exploitation for Credential Access
Collection
Discovery
Execution
Affected products and versions in CVE-2026-13043
- WatchGuard — WatchGuard Endpoint Security for Windows (Panda Kernel Memory Access Driver, pskmad.sys)
Vulnerable versions: all versions prior to 8.00.26.0012
Fixed in: 8.00.26.0012
Remediation for CVE-2026-13043
Patches
- WatchGuard Endpoint Security for Windows 8.00.26.0012
Immediate actions
- Update WatchGuard Endpoint Security for Windows to 8.00.26.0012 or later via the centralized management console
- Verify agent version compliance through agent version reporting
- Monitor for unexpected access to the PSMEMDriver device from non-vendor processes
- Hunt for the vulnerable pskmad.sys SHA-256 and for creation of Global\DOGPskMad* named objects by non-WatchGuard processes
Workarounds
- No vendor workaround documented; restrict device access and enforce least-privilege local accounts until patched
Longer-term hardening
- Enable Windows vulnerable driver blocklist / WDAC driver block rules and block the vulnerable pskmad.sys after compatibility testing
- Enable LSA protection (RunAsPPL) and Credential Guard and alert on LSASS access
- Enforce least-privilege for local accounts to limit who can open privileged driver devices
CVEs associated with CVE-2026-13043
Weaknesses (CWE) in CVE-2026-13043
Timeline of CVE-2026-13043
- Earlier Panda-lineage driver issues (CVE-2023-6330/6331/6332) cited by the researcher; WatchGuard later published WGSA-2024-00001/2/3 for pskmad_64.sys (pool corruption, OOB write, arbitrary memory read), showing a recurring weak driver surface.
- CVE-2026-13043 published and WatchGuard PSIRT advisory released: WatchGuard Endpoint Security for Windows before 8.00.26.0012 affected; fixed in 8.00.26.0012; no workaround.
- Juan Sacco publishes research on exploitpack.com detailing the PsOpenPacket000 handshake bypass, IOCTL operations and LSASS dump PoC; GBHackers dates the advisory to this day.
- Hunt feed reported active exploitation; the article text does not explicitly confirm it and no in-the-wild exploitation or CISA KEV listing was found in other sources.
- GBHackers publishes details of the PoC: memory transfer/mapping/unmapping/MSR operations, IA32_LSTAR read and LSASS dump (PID 1020) on Windows 11 25H2 with VBS/HVCI/kCET.
- Secondary analysis (Ayi NEDJIMI Consultants) updated: affected range prior to 8.00.26.0012, no confirmed in-the-wild exploitation, not in CISA KEV.
Sources cited for CVE-2026-13043
- Critical WatchGuard Endpoint Security Flaw Exposes Kernel and Process Memory (GBHackers)
- WatchGuard PSIRT Advisory CVE-2026-13043
- CVE-2026-13043: Panda Arbitrary Kernel/Process Memory Read (Juan Sacco, exploitpack.com)
- OpenCVE: CVE-2026-13043
- CVE-2026-13043 WatchGuard Kernel Memory analysis (Ayi NEDJIMI Consultants)
- WatchGuard Endpoint pskmad_64.sys Arbitrary Memory Read Vulnerability (WGSA-2024-00003)
- WatchGuard Endpoint pskmad_64.sys Pool Memory Corruption Vulnerability (WGSA-2024-00001)
- WatchGuard Endpoint pskmad_64.sys Out of Bounds Write Vulnerability (WGSA-2024-00002)
- Hack.lu 2026: Kernel Primitives to Code Execution on Windows 11 VBS/HVCI/kCET (Juan Sacco)
Detection coverage for TL-2026-3315
As of 2026-10-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3315 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.