WatchGuard Endpoint Security Prime Enhancements and Resolved Issues
Applies To: WatchGuard Endpoint Security Prime
For more information about new features, go to the What's New in WatchGuard Endpoint Security PowerPoint. Friends & Family testing involves a small number of invited partners and helps us to validate a release, collect feedback, and uncover bugs ahead of general availability. To participate in Friends & Family testing, send an email to the Friends & Family mailbox.
Protection and Agent Versions for WatchGuard Endpoint Security Prime 4.70.00
- Windows protection: 8.00.26.0011
- macOS protection: 3.08.00.0002
- Linux protection: 3.08.01.0000
- Android agent and protection: 3.14.3
- iOS agent and protection: 2.02.06.0001
- Windows agent: 1.25.12.0000
- macOS agent: 1.17.20.0000
- Linux agent: 1.17.00.0000
WatchGuard periodically updates Endpoint Security products and modules to provide enhancements and resolve reported issues. New versions roll out gradually to accounts. Some features and enhancements listed here might not be available to your account. When a new version is available, upgrade notifications appear as alerts in the upper-right corner of the management UI. If an upgrade is available, we recommend that you upgrade to the most recent version. If there is no alert in the management UI and you need to upgrade to the latest version of the product, contact your WatchGuard representative to request an upgrade. For more information, go to the Knowledge Base article: WatchGuard Endpoint Security Upgrade Schedule.
Release notes include customer-reported issues that were resolved in this release. Routine internal maintenance, localization updates, and other low-impact changes are not individually documented.
Latest Release
Release Date: 3 August 2026 (Aether 19.1 Update)
Enhancements
- The digital signature technology used to authorize programs as part of the Zero-Trust security model now includes support for short-lived certificates. This enhancement requires Windows protection v8.00.26.0011 or higher.
- Endpoint Security now supports these Linux distributions: Red Hat Enterprise Linux 10.0, 10.1, and 10.2; AlmaLinux 10.0, 10.1, and 10.2; Rocky Linux 10.0, 10.1, and 10.2; Oracle Linux 10.0, 10.1, and 10.2; CentOS Stream 10; AlmaLinux Kitten 10; SUSE Linux Enterprise 16; openSUSE Linux Enterprise 16.0; and Amazon Linux 2023. For more information on supported Linux distributions, go to Endpoint Security Installation Requirements in the WatchGuard Cloud Release Notes. Support for these distributions requires Linux protection v3.08.01.0000 or higher.
- The Endpoint Security software no longer requires Rosetta to run on ARM-based Mac devices. This feature requires macOS protection v3.08.00.0002 or higher.
Resolved Issues
- This release resolves BSOD errors caused by the NNSPICC.sys network interception driver.
- This release resolves an issue that caused continuous restarts of the protection service (PSANHost.exe). This caused the device to temporarily appear as unprotected in the management UI.
- This release resolves an issue in the Web Access Control feature where the category reported in block notifications was incorrect for pages that belonged to the Unknown category.
- This release resolves BSOD errors caused by the PSINReg.sys network interception driver when you connected specific dock stations or USB devices.
- This release resolves BSOD errors caused by a concurrency issue that affected the NNSPRV.sys network interception driver.
- This release resolves an issue that caused Network Attack Protection to reduce the Internet connection upload speed.
- This release resolves several performance issues.
- This release resolves an issue in the driver update that prevented the repair of the MSI cache.
- This release resolves BSOD errors caused by the PSINKNC.sys driver on computers where there was a large number of running processes that generated multiple input/output operations.
- We have re-signed Device Control drivers to prevent errors on legacy Windows 10 (th1) systems.
- This release resolves BSOD errors caused by the PSINFILE.sys driver.
- This release resolves an issue where Device Control local alerts did not show when the security software blocked USB devices.
- We have updated the SQLite3.dll library to resolve vulnerabilities.
- This release resolves a security software vulnerability that could enable privilege escalation.
Previous Releases
Enhancements
- Version 1.25.12.000 of the Windows Agent includes these enhancements:
- Both administrator and non-administrator users can configure encryption (PIN or password) for Full Encryption.
- Both administrator and non-administrator users can restart a computer from a protection update or Patch Management alerts.
- Both administrator and non-administrator users can retry actions from the initial installation dialog box.
Enhancements
- On the Settings > My Alerts page, you can now enable email notifications for incidents. When configured, Endpoint Security sends an email notification when it detects an incident.
- In the Privacy section of a workstations and servers settings profile, you can now enable or disable the Allow Anti-Exploit Technology to Send Diagnostic Information option. When enabled, Endpoint Security automatically sends diagnostic data for any detection made by the anti-exploit technology to the WatchGuard Security team for review. This feature requires Windows protection v8.00.26.0011 or higher.
- You can now export and import settings profiles. For more information, go to Manage Settings Profiles in Help Center.
Resolved Issues
- Minor updates and bug fixes.
Enhancements
- Version 3.14.3 of the WatchGuard Mobile Security app for Android includes these enhancements:
- Improved device information updates. The Mobile Security app now checks for relevant changes on Android devices every 7 days and reports them automatically to the WatchGuard servers (for example, operating system version changes).
- The Android Mobile Security app no longer includes code associated with operating system versions the app no longer supports. This enhancement reduces the attack surface and minimizes potential vulnerabilities.
- The Android Mobile Security app now collects more information for error analysis. This allows for more efficient identification and resolution of issues.
Resolved Issues
- Minor updates and bug fixes.
Enhancements
- Version 2.02.05 of the WatchGuard Mobile Security app for iOS includes these enhancements:
- Improved response time when you access the Anti-Theft feature.
- You no longer need to grant the app the Local Device Access permission when you install it without an MDM solution.
- Optimized installation of the app when you do not need to grant permissions to the app.
Resolved Issues
- This release resolved an issue where the WatchGuard Mobile Security app for iOS obtained the device location when you opened it.
- This release resolved an issue where the Issues or Protections sections in the main window of the app did not show correctly.
- This release resolved an issue where customer data was incorrectly sent to Support when customers reported an issue with the iOS protection.
Enhancements
- End users without the required permissions can no longer restart a computer from a protection update or from Patch Management alerts. The user must wait for the predefined timeout to expire or restart the computer on their own.
- End users without the require permissions can no longer retry actions from the initial patch installation window. Endpoint Security Prime will retry the action automatically after a period of time.
Resolved Issues
- This release resolved an issue where the installer did not request privilege elevation in certain cases, which prevented the application of necessary settings.
- This release resolved the CVE-2026-41286 vulnerability, which could cause the WatchGuard Agent to crash when it received invalid communications.
- This release resolved the CVE-2026-41287 vulnerability, which could cause the WatchGuard Agent to crash when it processed certain messages.
- This release resolved the CVE-2026-41288 vulnerability, which could enable a local user to gain elevated privileges in the system.
- This release resolved the CVE-2026-6787 vulnerability, which could enable the execution of processes with elevated privileges on the system.
- This release resolved the CVE-2026-6788 vulnerability, which could enable unauthorized users to gain elevated privileges on the system.
Enhancements
- Initial release of product. For information on WatchGuard Endpoint Security Prime, go to About Endpoint Security Prime in Help Center.