Ubiquiti UniFi Protect Application patch for CVE-2026-77537
Security Patch Release
Summary
Hide ▲
Show ▼
Ubiquiti released security patches for CVE-2026-77537 in UniFi Protect Application, fixing an improper input validation flaw that could let unauthenticated attackers compromise unpatched devices remotely. The fix is available in UniFi Protect Application 7.2.105 or later. Ubiquiti said the attacks are low-complexity and require no user interaction. The company did not disclose in-the-wild exploitation before patching.
Related Happenings
Adobe security patch release for CVE-2026-48362
Security Patch Release
H score43
First: 11.08.2026 19:50
Last: 11.08.2026 19:50
Sources 1
About this happening:
Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Adobe security patch release for CVE-2026-48362
Security Patch ReleaseAbout this happening: Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Ubiquiti UniFi OS security updates (multiple vulnerabilities)
Security Patch Release
H score28
First: 22.05.2026 15:00
Last: 22.05.2026 15:00
Sources 1
About this happening:
Ubiquiti released security updates for UniFi OS to close five vulnerabilities, including three maximum-severity flaws that could let remote attackers without...
Ubiquiti UniFi OS security updates (multiple vulnerabilities)
Security Patch ReleaseAbout this happening: Ubiquiti released security updates for UniFi OS to close five vulnerabilities, including three maximum-severity flaws that could let remote attackers without...
Latest development: 24.06.2026 15:32
CISA warned that threat actors were targeting CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 in Ubiquiti UniFi OS devices after the flaws were patched in UniFi OS Server 5.0.8, and multiple users reported that the bugs were exploited in the wild, likely as zero-days, to create rogue administrator accounts named John Sim.
Ivanti EPMM patch release for CVE-2026-5786, CVE-2026-5787, CVE-2026-5788, and CVE-2026-7821
Security Patch Release
H score66
First: 07.05.2026 18:20
Last: 07.05.2026 18:20
Sources 1
About this happening:
Ivanti released a security update for on-prem Endpoint Manager Mobile (EPMM) covering CVE-2026-5786, CVE-2026-5787, CVE-2026-5788, and CVE-2026-7821. The patch addresses high-seve...
Ivanti EPMM patch release for CVE-2026-5786, CVE-2026-5787, CVE-2026-5788, and CVE-2026-7821
Security Patch ReleaseAbout this happening: Ivanti released a security update for on-prem Endpoint Manager Mobile (EPMM) covering CVE-2026-5786, CVE-2026-5787, CVE-2026-5788, and CVE-2026-7821. The patch addresses high-seve...
Latest development: 07.05.2026 20:55
Ivanti released fixes for CVE-2026-5786, CVE-2026-5787, CVE-2026-5788, and CVE-2026-7821 in Endpoint Manager Mobile (EPMM). The updates apply only to on-prem EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1, and Ivanti said the issues are not present in Ivanti Neurons for MDM, Ivanti EPM, Ivanti Sentry, or other Ivanti products.
Ivanti security patch release for CVE-2026-1281
Security Patch Release
H score46
First: 30.01.2026 06:43
Last: 30.01.2026 06:43
Sources 1
About this happening:
Ivanti released security updates for Ivanti Endpoint Manager Mobile (EPMM) after disclosure of two critical zero-day flaws that can enable unauthenticated remote...
Ivanti security patch release for CVE-2026-1281
Security Patch ReleaseAbout this happening: Ivanti released security updates for Ivanti Endpoint Manager Mobile (EPMM) after disclosure of two critical zero-day flaws that can enable unauthenticated remote...
Latest development: 13.02.2026 00:05
Reported on Feb. 12, 2026, attacks tied to Ivanti Endpoint Manager Mobile (EPMM) had struck the European Commission and agencies of the Dutch and Finnish governments after Ivanti disclosed CVE-2026-1281 and CVE-2026-1340 on Jan. 29. The European Commission said its central infrastructure managing mobile devices was hit on Jan. 30, with staff names and mobile numbers compromised, while Valtori said an attack of the same nature affected around 50,000 people associated with Finland's central government and leaked names, email addresses, phone numbers, and other device details.
Timeline
-
26.08.2026 16:17 2 articles · 1h ago
Ubiquiti releases patches for three maximum-severity UniFi flaws
Mitigation Patch UpdateUbiquiti released security patches for CVE-2026-77537 in UniFi Protect Application, CVE-2026-77550 in UniFi OS devices or instances, and CVE-2026-77554 in UniFi Talk Application. The flaws can be exploited remotely without privileges and in low-complexity attacks that do not require user interaction; the fixed versions are UniFi Protect Application 7.2.105 or later, UniFi Talk Application 5.3.2 or later, and UniFi OS Server 5.1.21 and earlier.
Show sources
- Ubiquiti patches three max severity security vulnerabilities — www.bleepingcomputer.com — 26.08.2026 16:17
- Ubiquiti patches three max severity security vulnerabilities — www.bleepingcomputer.com — 26.08.2026 16:17