Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation

2026-07-09T02:51:42Z09265b5ad95b85b0400c9fc154660b9f6540e277df0caf80c3d083b288b22f92
active-exploitationaptauthentication-bypassbackdoorcloud-vm-escapecommand-injectiondata-breachknown-exploited-vulnerabilitieslinux-kvmsecurity-patchspywarevulnerability

What happened

Multiple high-impact security incidents reported: Ubiquiti released fixes for seven UniFi OS vulnerabilities including critical command-injection CVE-2026-50746 (CVSS 10.0). A critical Gitea Docker authentication-bypass (CVE-2026-20896, CVSS 9.8) is under active exploitation, and CERT/CC disclosed an unpatched Tenda router backdoor (CVE-2026-11405) allowing full admin access. Other notable items include a 35 GB Accenture source-code/data breach, a Telegram-hosted RedWing Android spyware-for-hire operation, CISA additions to the KEV catalog and deployment of Anthropic’s Mythos for code scanning

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
09265b5ad95b85b0400c9fc154660b9f6540e277df0caf80c3d083b288b22f92
Enrichment time
2026-07-09T02:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.