Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities SC Media

Ubiquiti patches 3 critical remote code execution vulnerabilities

  • What: Ubiquiti patches 3 critical remote code execution vulnerabilities
  • Impact: Fixes flaws that allow unauthenticated attackers to compromise devices
Read Full Article →

Vulnerability Management Ubiquiti patches 3 critical remote code execution vulnerabilities August 26, 2026 Share By SC Staff Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges, based on information published by Bleeping Computer. The vulnerabilities include improper input validation in the UniFi Protect Application (CVE-2026-77537), a CRLF injection flaw in UniFi OS devices (CVE-2026-77550), and a command injection flaw in the UniFi Talk Application (CVE-2026-77554). These issues allow unauthenticated attackers to compromise devices, bypass authentication, and execute commands. Ubiquiti has not disclosed if these vulnerabilities were exploited in the wild, but they can be exploited with low complexity and no user interaction. This follows a recent patch for 18 other critical-severity issues affecting a wide range of Ubiquiti products. Threat actors have frequently targeted Ubiquiti devices to build botnets, as seen with the FBI's disruption of the Russian Moobot botnet. In June, CISA mandated federal agencies to secure systems against similar critical UniFi OS vulnerabilities that were actively exploited. The company has released updates for UniFi Protect Application 7.2.105 or later, UniFi Talk Application 5.3.2 or later, and UniFi OS Server 5.1.21 and earlier. Source: Bleeping Computer SC Staff Related Vulnerability Management CISA adds Oracle WebLogic bug to its list of exploited vulnerabilities Steve Zurier August 25, 2026 Experts say exploiting WebLogic middleware gives attackers access to an enterprise's core business apps. Vulnerability Management WordPress plugin vulnerabilities allow admin account takeover SC Staff August 24, 2026 The vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, can be chained together to bypass authentication. Vulnerability Management Metal Gear Online 3 vulnerability allowed remote code execution SC Staff August 24, 2026 The vulnerability, discovered by researcher Alice Cecchetto and detailed by CERT/CC, stemmed from a heap-based buffer overflow in the game's player-removal mechanism. Related Events Cybercast State of Vulnerability Management Thu Sep 10 Cybercast Why Mythos is the cybersecurity crisis we need On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds

Share this article