A reported critical flaw in the Panda Kernel Memory Access Driver used by WatchGuard and Panda endpoint products could let a local authenticated attacker bypass an intended driver-authentication control and read sensitive kernel or process memory. The issue is tracked as CVE-2026-13043 and carries a reported CVSS score of 9.3.

Research describing the issue shows access to a driver interface that can service privileged memory operations. Demonstrated impacts include reading process memory and kernel-address information; the reporting does not establish arbitrary code execution. A local foothold and access to an affected installed component remain important prerequisites.

Defenders should first establish whether the affected driver is present across their estate and obtain vendor-confirmed fixed versions. Endpoint teams can also review device access controls, investigate unexpected access to the driver interface, and consider blocking the driver only after compatibility testing.

The distinction between local post-compromise capability and remote initial access is important for prioritization: this is especially relevant where endpoint users may already have a foothold, or where credential-bearing processes need added protection.

Source: GBHackers; ExploitPack research.

By Allan