LIVE · cybersecurity feed
Live wire
vendor3 exploited in the wild

Ui

30 CVEs published in the last four months and 12 stories. Exploited flaws first.

Critical11
High19
Medium0
Exploited (KEV)3

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-34908exploited10criticalunifi os serverA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi107d ago
CVE-2026-34910exploited10criticalunifi os serverA malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in Uni107d ago
CVE-2026-34909exploited10criticalunifi os serverA malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS device107d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-34908exploited10criticalunifi os serverA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi107d ago
CVE-2026-34910exploited10criticalunifi os serverA malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in Uni107d ago
CVE-2026-34909exploited10criticalunifi os serverA malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS device107d ago
CVE-2026-5074610criticalunifi connect applicationA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi65d ago
CVE-2026-507489.9criticalunifi accessA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnera65d ago
CVE-2026-507479.9criticalunifi talk applicationA malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Inject65d ago
CVE-2026-544029.9criticalunifi os serverA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnera65d ago
CVE-2026-551159.9criticalunifi protectA malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF)65d ago
CVE-2026-544009.1criticalunifi accessA malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerab65d ago
CVE-2026-330009.1criticalunifi os serverA malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulner107d ago
CVE-2026-551169criticalunifi connectA malicious actor with access to the network and under certain network configurations could exploit an Improper Ac65d ago
CVE-2026-568418.8highunifi protectA malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulne65d ago
CVE-2026-551148.8highunifi network applicationA malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerabi65d ago
CVE-2026-544048.8highunifi dream machine beast firmwareA malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Inject65d ago
CVE-2026-544068.7highunifi network applicationA malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability foun65d ago
CVE-2026-544078.6highunifi protectA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi65d ago
CVE-2026-544038.6highunifi os serverA malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices65d ago
CVE-2026-544088.6highunifi protectA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi65d ago
CVE-2026-551178.6highunifi accessA malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Ap65d ago
CVE-2026-551188.3highunifi network applicationA malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper65d ago
CVE-2026-551198.1highunifi talk applicationA malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerabi65d ago
CVE-2026-349117.7highunifi os serverA malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found107d ago
CVE-2026-544017.7highunifi os serverA malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF)65d ago
CVE-2026-544057.5highunifi network applicationA malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in Uni65d ago
CVE-2026-568427.5highunifi network applicationA malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization65d ago
CVE-2026-551117.5highprotect floodlight firmwareA malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Protect F65d ago
CVE-2026-551107.5highunifi os serverA malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharin65d ago
CVE-2026-551127.5highunifi dream machine pro firmwareA malicious actor with access to the network and low privileges and under certain conditions could exploit an Impr65d ago
CVE-2026-551137.5highunifi talk applicationA malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability foun65d ago
CVE-2026-544097.5highunifi protectA malicious actor with access to the network and under certain conditions could exploit an Improper Initialization65d ago

Filter the full tracker by Ui

Our coverage of Ui

ai

BreachX Launches Typhon, India-Built Sovereign Cybersecurity AI for Zero-Day Discovery and Defense

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

nation-state

Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

security

Friday Squid Blogging: Squid on a Stick at the New York State Fair

Looks tasty. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

breach

Russian data centers face new security requirements amid Ukraine's drone threats

Russia's data centers are concentrated in areas increasingly exposed to Ukrainian drone attacks. The Kremlin wants them to stiffen their physical defenses.

finance

Large Enterprises Targeted in Fake Merger & Acquisition Scams

Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.

nation-state

Researchers built a $7 gadget for anyone paranoid about hidden cameras in hotel rooms

Most of us, staying in a hotel room or a vacation rental, have wondered at least once whether we’re safe there, whether someone might be watching or recording us without our knowledge. The thought alone leaves a bitter taste in the mouth. A team from the Korea Advanced Institute of Science and Technology (KAIST), working with the National University of Singapore and Singapore Management University

ransomware

Security Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Hack One Robot, Reach the Next: Unitree G1 Security Flaws Rhysida Ransomware Group Targets Berlin Government Ahead […]

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

vulnerability

White House bans foreign-made equipment for power generation over cyber backdoor concerns

The Trump administration is banning the acquisition of foreign-made components used to manage electricity and power, alleging that “certain foreign actors are increasingly creating and exploiting vulnerabilities” in the technology.

nation-state

Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure

The order says any foreign-produced equipment deemed to pose national security risks can’t be purchased or installed. The post Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure appeared first on CyberScoop.

vulnerability

Ubiquiti patches three max severity security vulnerabilities

Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges. [...]

phishing

Bogus recruiters go after high-value corporate credentials on mobile

Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium. Attackers are using a technique called browser-in-the-browser, or BitB, which CTM360 documented in earlier research on recruitment phishing. They scrape public profile data and use it to craft convincing scheduling flows designed to get past