Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-77554: UniFi Talk lets network attacker run commands

CVE-2026-77554 · published 8 days ago
Summary

The UniFi Talk application does not properly check data it receives, so someone on the same network could trick it into running commands on the server. This could let an attacker take control of the device or access sensitive information. Apply the latest software update or contact the vendor for a fix as soon as possible.

What to do
  • Update ubiquiti inc unifi talk application to version 5.3.2 or later.
Affected software
VendorProductAffected versions
ubiquiti inc unifi talk application < 5.3.2
Original advisory text
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device.
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device.
Severity
10.0 Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-20Improper Input Validation
Timeline
Published26 Aug 2026
Updated30 Aug 2026
First seen26 Aug 2026
Sources
CVE-2026-77554 · MITRE
Monitor software like this
Free during beta