Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation

2026-07-09T08:51:51Z21abcd41a8e717c93481759de856019436898ceb218a0bbf23947f18c31308ef
AccentureAdobe ColdFusionAndroid spywareCISACVE-2026-11405CVE-2026-20896CVE-2026-50746GiteaJanuscape KVM bug","VM escape","hypervisor vulnerability","ArmJoomShaper SP Page BuilderJoomlack Page BuilderKnown Exploited VulnerabilitiesLangflowRedWingTelegramTendaUbiquitiUniFi OSauthentication bypasscommand injectiondata breachmalware-as-a-serviceprivilege escalationrouter backdoorsource code leak

What happened

A batch of high-impact security events: Ubiquiti patched seven UniFi OS vulnerabilities including critical CVE-2026-50746 (CVSS 10.0) enabling command injection in UniFi Connect; a 35 GB Accenture data breach (source code, keys, Azure credentials) was disclosed; RedWing Android spyware is being sold via Telegram as malware-as-a-service; CISA added multiple products to its KEV list (including Adobe ColdFusion and several page-builder plugins); a critical Gitea Docker authentication-bypass (CVE-2026-20896, CVSS 9.8) is under active exploitation; CERT/CC disclosed an unpatched Tenda router backdo

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
21abcd41a8e717c93481759de856019436898ceb218a0bbf23947f18c31308ef
Enrichment time
2026-07-09T08:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.