3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77557 — A malicious actor with access to the network could exploit an Improper Access Control

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77557

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on the device. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77554 — A malicious actor with access to the network could exploit an Improper Input Validation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77554

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device. CVSSv3.1 10.0 (CRITICAL)

CWECWE 20TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77553 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77553

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device. CVSSv3.1 9.9 (CRITICAL)

CWECWE 284TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77552 — A malicious actor with access to the network could exploit an Improper Input Validation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77552

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Video Bridge to execute a Command Injection on the device. CVSSv3.1 9.8 (CRITICAL)

CWECWE 20TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77551 — A malicious actor with access to the network and under certain conditions could exploit

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77551

A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Connect Display Cast Pro to escalate privileges on the device. CVSSv3.1 9.0 (CRITICAL)

CWECWE 284TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77550 — A malicious actor with access to the network could exploit an Improper Neutralization of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77550

A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances. CVSSv3.1 10.0 (CRITICAL)

CWECWE 93TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77549 — A malicious actor with access to the network and under certain conditions could exploit

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77549

A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances. CVSSv3.1 9.0 (CRITICAL)

CWECWE 93TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
728 × 90 / responsive · programmatic ad slot
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77548 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77548

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device. CVSSv3.1 9.9 (CRITICAL)

CWECWE 20TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77547 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77547

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. CVSSv3.1 9.9 (CRITICAL)

CWECWE 20TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77546 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77546

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. CVSSv3.1 9.9 (CRITICAL)

CWECWE 20TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77532 — A malicious actor with access to an adjacent network could exploit a Buffer Overflow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77532

A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwitch to initiate a Remote Code Execution on such device. CVSSv3.1 9.6 (CRITICAL)

CWECWE 122TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-18080 — ERP: The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18080

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 1.17.8 via the save_attachments() function. This is due to missing file extension validation and missing path normalization when CRM Email Connect processes inbound IMAP email attachments. This makes it possible for unauthenticated attackers to send a crafted email to the site's configured inbound mailbox CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDErpTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 11:00Z
CRIT

VMs won't contain cyber-capable agents

Trail of Bits·blog.trailofbits.comCVE-2026-53359CVE-2026-95390day

Trail of Bits researchers demonstrated that GPT 5.6-Cyber autonomously escaped a QEMU/KVM VM three times using a combination of disclosed vulnerabilities, unpatched distribution bugs, and zero-day exploits in QEMU, Linux KVM, and libslirp. The agent operated for ~12 hours, chaining multiple memory corruption and privilege escalation primitives to achieve host kernel execution and flag exfiltration. The research challenges the assumption that standard VMs provide adequate containment for advanced AI agents and highlights critical gaps in distribution patch cycles and virtualization attack surface.

SRFOsTACTA0004TACTA0002SRFCloudOSLinuxSWFirecrackerSWKvmSWLibslirp
92
Edit Score
3w ago
2026-08-26 10:16Z
CRIT

CVE-2026-80349 — TarsWeb: decides whether a request comes from a trusted local caller using a client-controlled

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80349

TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header. app.js sets Koa's proxy option to true without naming which upstream proxies may be trusted and without limiting the number of forwarded hops, so the request address Koa reports is taken from the X-Forwarded-For header supplied by the caller. In midware/ssoMidware.js a single branch covers both the ignored-path list and the ignoreIps allowlist from config/loginConf.js, which CVSSv3.1 9.8 (CRITICAL)

CWECWE 290VNDTarswebTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 10:16Z
HIGH

CVE-2026-80348 — TarsWeb: enforces its per-application roles by calling AuthService from individual controller methods, and four

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80348

TarsWeb enforces its per-application roles by calling AuthService from individual controller methods, and four methods in app/controller/patch/PatchController.js make no such call. uploadAndPublish accepts a package upload and then builds and dispatches a deployment task to every server matching the supplied application and module name, while its sibling uploadPatchPackage, which only stores the package, does check developer authorization first. The only precondition uploadAn CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDTarswebTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 10:16Z
CRIT

CVE-2026-77545 — A malicious actor with access to the network, low privileges and under certain conditions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77545

A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances. CVSSv3.1 9.0 (CRITICAL)

CWECWE 489TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
3w ago
2026-08-26 10:16Z
CRIT

CVE-2026-77543 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77543

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. CVSSv3.1 9.9 (CRITICAL)

CWECWE 20TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
3w ago
2026-08-26 10:16Z
CRIT

CVE-2026-77542 — A malicious actor with access to the network and high privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77542

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device. CVSSv3.1 9.1 (CRITICAL)

CWECWE 20TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-26 10:16Z
CRIT

CVE-2026-77541 — A malicious actor with access to the network and high privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77541

A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-26 10:16Z
CRIT

CVE-2026-77540 — A malicious actor with access to the network and high privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77540

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device. CVSSv3.1 9.1 (CRITICAL)

CWECWE 20TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-26 10:16Z
CRIT

CVE-2026-77539 — A malicious actor with access to the network and high privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77539

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device. CVSSv3.1 9.1 (CRITICAL)

CWECWE 20TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-26 10:16Z
HIGH

CVE-2026-77538 — A malicious actor with access to the network could exploit an Improper Access Control

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77538

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to escalate privileges within the UniFi Connect Application. CVSSv3.1 8.2 (HIGH)

CWECWE 284TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 10:16Z
CRIT

CVE-2026-77537 — A malicious actor with access to the network could exploit an Improper Input Validation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77537

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device. CVSSv3.1 10.0 (CRITICAL)

CWECWE 20TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
3w ago
2026-08-26 10:16Z
CRIT

CVE-2026-77536 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77536

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances. CVSSv3.1 9.9 (CRITICAL)

CWECWE 284TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
3w ago
2026-08-26 10:16Z
CRIT

CVE-2026-77535 — A malicious actor with access to the network and high privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77535

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Command Injection on an adopted device. CVSSv3.1 9.1 (CRITICAL)

CWECWE 20TYPVulnerability
9.1
CVSS v3.1
96
Edit Score