Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation
2026-07-09T08:51:51Z•21abcd41a8e717c93481759de856019436898ceb218a0bbf23947f18c31308ef
AccentureAdobe ColdFusionAndroid spywareCISACVE-2026-11405CVE-2026-20896CVE-2026-50746GiteaJanuscape KVM bug","VM escape","hypervisor vulnerability","ArmJoomShaper SP Page BuilderJoomlack Page BuilderKnown Exploited VulnerabilitiesLangflowRedWingTelegramTendaUbiquitiUniFi OSauthentication bypasscommand injectiondata breachmalware-as-a-serviceprivilege escalationrouter backdoorsource code leak
What happened
A batch of high-impact security events: Ubiquiti patched seven UniFi OS vulnerabilities including critical CVE-2026-50746 (CVSS 10.0) enabling command injection in UniFi Connect; a 35 GB Accenture data breach (source code, keys, Azure credentials) was disclosed; RedWing Android spyware is being sold via Telegram as malware-as-a-service; CISA added multiple products to its KEV list (including Adobe ColdFusion and several page-builder plugins); a critical Gitea Docker authentication-bypass (CVE-2026-20896, CVSS 9.8) is under active exploitation; CERT/CC disclosed an unpatched Tenda router backdo
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 21abcd41a8e717c93481759de856019436898ceb218a0bbf23947f18c31308ef
- Enrichment time
- 2026-07-09T08:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.