Max severity Ubiquiti UniFi flaw may allow account takeover

2026-03-19T13:23:36Z6690ef8cfdc0252074d498ff376ff97eb483f117a6f3d83afdb63e88e9a2c5b7
Android malwareAura data breachCISACisco Secure FMCConnectWiseDarkSwordGlassWormInterlock ransomwareMicrosoft IntuneMicrosoft SharePointPerseusRCEScreenConnectStryker breachUbiquiti UniFiUniFi Network ApplicationXSSZimbraaccount takeoverdata breachiOS exploitinfostealersignature verification vulnerabilitysupply-chainzero-day

What happened

BleepingComputer roundup: multiple high- and maximum-severity vulnerabilities and active exploit campaigns were reported. Ubiquiti patched two UniFi Network Application flaws including a maximum-severity account-takeover issue; Cisco Secure FMC RCE has been exploited in zero-day ransomware attacks; a critical Microsoft SharePoint flaw is now under active exploitation; and CISA ordered feds to patch an actively exploited Zimbra XSS. Other notable incidents include CISA guidance after a Microsoft Intune compromise used against Stryker, the Perseus Android malware harvesting user notes, the DarkS

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
6690ef8cfdc0252074d498ff376ff97eb483f117a6f3d83afdb63e88e9a2c5b7
Enrichment time
2026-03-19T13:23:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.