LIVE · cybersecurity feed
Live wire
CVE-2026-15409 · Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeterAnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodesCVE-2026-60004 · Hackers now exploit critical Gitea flaw in code injection attacksEmployee benefits platform Paylogix says hackers stole financial and health dataU.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure BreachesCVE-2026-61979 · Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as VulnerableCVE-2024-28224 · A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClawAustralia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attack
vulnerability

Ubiquiti patches three max severity security vulnerabilities

Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges. [...]

zeroday.news ·

Ubiquiti has released security updates to address three critical vulnerabilities that could allow unauthenticated remote attackers to compromise affected devices. The patches were issued on August 26, 2026, for flaws impacting the UniFi Protect Application, UniFi Talk Application, and UniFi OS.

One vulnerability, tracked as CVE-2026-77537, is an improper input validation issue within the UniFi Protect Application, a video surveillance management platform. This flaw could be exploited by unauthenticated attackers to compromise unpatched devices.

Another severe vulnerability, CVE-2026-77550, is a CRLF injection flaw affecting UniFi OS devices and instances. Ubiquiti stated that a malicious actor with network access could exploit this weakness to bypass authentication.

The third maximum-severity vulnerability, CVE-2026-77554, is a command injection flaw found in the UniFi Talk Application, a Voice over IP (VoIP) phone system. This issue also stems from improper input validation.

Ubiquiti has confirmed that these vulnerabilities can be exploited in low-complexity attacks that do not require user interaction. The company has not yet disclosed whether any of these specific flaws have been exploited in the wild prior to the release of the patches.

The necessary updates are included in UniFi Protect Application version 7.2.105 or later, UniFi Talk Application version 5.3.2 or later, and UniFi OS Server version 5.1.21 and earlier.

This round of patches follows a broader security update released on Thursday, August 22, 2026, which addressed 18 other critical-severity issues across various Ubiquiti products. These included the UniFi OS Server, UniFi Network Application, UniFi Protect AI Key, and a range of routers, gateways, NAS devices, and surveillance systems.

Threat intelligence data indicates over 100,000 UniFi OS instances are exposed online, though this figure may include historical scan results and does not differentiate between live systems, honeypots, or those already secured.

Ubiquiti products have been a target for state-backed hacking groups and cybercriminals, who have leveraged them to create large-scale botnets for concealing malicious activities. For instance, in February 2024, the FBI disrupted the Moobot botnet, which utilized Ubiquiti Edge OS routers to proxy traffic for the Russian Main Intelligence Directorate of the General Staff (GRU) in cyberespionage operations.

More recently, in June, the Cybersecurity and Infrastructure Security Agency (CISA) issued a directive requiring federal agencies to patch three other maximum-severity UniFi OS vulnerabilities within three days. These earlier flaws, patched in May, were actively being exploited in the wild and could be chained to achieve remote code execution with elevated privileges, as demonstrated by cybersecurity researchers.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Four in Five AI Tools Run with No IT Oversight, New Research Finds

Reco report reveals growing shadow AI problem and surge in vulnerability disclosures

CVE-2026-15409critical

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. It is the shared attack surface where state-sponsored threat actors and financially motivated criminal grou

phishingcritical

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes

A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. “By leveraging a critical flaw – the use of bare relative paths – the investigation unraveled a reseller supply chain of 506 domains and 168 storefront brands active since early 2024. Despite leveraging advanced AI to mim

CVE-2026-60004critical

Hackers now exploit critical Gitea flaw in code injection attacks

Attackers are actively exploiting a critical code injection vulnerability (CVE-2026-60004) in the self-hosted Gitea Git service. The flaw allows authenticated users with write access to execute arbitrary shell commands, and with default open registration, unauthenticated attackers can exploit it by creating an account. Gitea has released version 1.27.1 to address the issue, and CISA has ordered U.S. federal agencies to patch within three days due to active exploitation, with reports indicating cryptocurrency mining malware deployment.

security

Election official says Tina Peters would be consultant, won’t have access to election systems

Shasta County registrar Clint Curtis told CyberScoop he needs Peters to help manage the county’s 2026 elections and he’s not concerned about her past conviction. The post Election official says Tina Peters would be consultant, won’t have access to election systems appeared first on CyberScoop.

security

Interpol Operation Jackal IV Identifies 263 Cybercrime Suspects

Interpol operation leads to 58 arrests and identifies 263 suspects across 22 countries