CVE-2026-77549
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9epss 0.3%
exploitation probability
0.3%top 77% of all CVEs
observed exploitation
nono source reports it
A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
Ubiquiti Inc · Cloud GatewaysUbiquiti Inc · Cloud KeysUbiquiti Inc · Dream MachinesUbiquiti Inc · Dream RoutersUbiquiti Inc · Dream WallUbiquiti Inc · Enterprise Firewall CoreUbiquiti Inc · Enterprise Fortress GatewayUbiquiti Inc · Enterprise Network Attached StorageUbiquiti Inc · Enterprise Network Video RecordersUbiquiti Inc · ExpressUbiquiti Inc · Express 7Ubiquiti Inc · Network Attached StorageUbiquiti Inc · Network Video RecordersUbiquiti Inc · UniFi OS Server