CVE-2026-77545CWE-489

CVE-2026-77545

Critical · published August 26, 2026

CVSS v3.1
9.0
EPSS
0%
Percentile
11.8
In the wild
Unconfirmed
What it is

A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.

The record
Technical detail
CVSS v3.1
9.0 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00214 · 11.8th percentile
Weakness
CWE-489 · Active Debug Code
Published
2026-08-26T14:16Z
References (1)
EPSS history
Timeline
  • 28 AUG 06:53Z
    EPSS moved — → 0%
    epss
  • 26 AUG 10:13Z
    A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain…
    cvelistv5