PatchSiren

Watchdog CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Watchdog CVE published 2026-09-20

CVE-2026-92254

A vulnerability in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Microsoft Windows allows local, low-privileged attackers to delete arbitrary files with SYSTEM privileges. This is due to missing authorization in the IOCTL handlers of the wsdkd.sys kernel drivers. The vulnerability could potentially disable security products or destabilize the operating system via crafted IOC [truncated]

MEDIUM WatchDog CVE published 2026-09-20

CVE-2026-92253

CVE-2026-92253 is a vulnerability in WatchDog Anti-Virus 1.8.640 on Windows, allowing local, low-privileged attackers to cause a quarantined file to be written to an arbitrary filesystem location. This may enable modification of protected files or SYSTEM-level code execution through DLL hijacking. The vulnerability is caused by improper link resolution before file access in the quarantine restoration proc [truncated]

MEDIUM WatchDog CVE published 2026-09-20

CVE-2026-92252

CVE-2026-92252 is a vulnerability in WatchDog Anti-Virus on Windows, where incorrect default permissions allow local, low-privileged users to modify, replace, or delete antivirus binaries and configuration files. This vulnerability can potentially disable antivirus protection or enable privileged code execution if modified binaries are loaded by an elevated WatchDog process. The vulnerability exists becau [truncated]