Critical severity10.0NVD Advisory· Published Aug 26, 2026· Updated Aug 28, 2026
CVE-2026-77537
CVE-2026-77537
Description
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
Affected products
2Patches
Vulnerability mechanics
References
1News mentions
4- ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and MoreThe Hacker News · Aug 31, 2026
- Three 10.0 security flaws fixed across Ubiquiti’s UniFi lineCyberScoop · Aug 26, 2026
- 21 Critical Ubiquiti UniFi Flaws Enable Authentication Bypass, Command Injection and Privilege EscalationCyber Security News · Aug 26, 2026
- Ubiquiti UniFi: 16 Critical Vulnerabilities Disclosed Together Enable RCE and Auth BypassVypr Intelligence · Aug 26, 2026