Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-77554: UniFi Talk lets network attacker run commands
CVE-2026-77554 · published 8 days ago
Summary
The UniFi Talk application does not properly check data it receives, so someone on the same network could trick it into running commands on the server. This could let an attacker take control of the device or access sensitive information. Apply the latest software update or contact the vendor for a fix as soon as possible.
What to do
- Update ubiquiti inc unifi talk application to version 5.3.2 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ubiquiti inc | unifi talk application | < 5.3.2 |
Original advisory text
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device.
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device.
Severity
10.0
Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-20Improper Input Validation
Timeline
Published26 Aug 2026
Updated30 Aug 2026
First seen26 Aug 2026
Monitor software like this
Free during beta