← All briefings

Ubiquiti UniFi Talk Application · Ubiquiti UniFi Protect and Access Applications · JFrog Artifactory

Date: 2026-08-29 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership

Executive Summary

The highest-priority new risks are critical Ubiquiti UniFi command-injection vulnerabilities with high EPSS scores, including CVE-2026-77554 at 0.99, and a JFrog Artifactory authentication weakness that may grant unauthenticated administrative access under default configuration. A new Pimcore account-takeover vulnerability has an EPSS score of 0.67. PaperCut NG/MF exploitation has materially escalated: the vendor issued a second emergency patch after bypasses of initial fixes were identified.

Critical Vulnerabilities

CVE-2026-77554 — Ubiquiti UniFi Talk Application

  • Severity: CVSS 10.0
  • EPSS: 0.99 — very high exploitation probability
  • Technical detail: An improper input-validation flaw allows a network-accessible attacker to execute commands on the host device. The vulnerable product range is UniFi Talk Application versions below 5.3.2. Exploitation requires network access, but exposure may be significant where UniFi management services are reachable from untrusted or broadly accessible internal networks.
  • Exploitation status: No confirmed exploitation reported in the collected data.
  • Remediation: Upgrade UniFi Talk Application to version 5.3.2 or later. Restrict management-plane access, verify that UniFi services are not internet-exposed, and review controller and device logs for unexpected administrative activity.

CVE-2026-77548 / CVE-2026-77547 / CVE-2026-77546 / CVE-2026-77543 — Ubiquiti UniFi Protect and Access Applications

  • Severity: CVSS 9.9
  • EPSS: 0.80 for the listed command-injection vulnerabilities — high exploitation probability
  • Technical detail: Multiple improper input-validation vulnerabilities in UniFi Protect and UniFi Access can enable command execution on host devices. The affected versions are Protect below 7.2.105 and Access below 4.3.5. Exploitation generally requires network access and, for some issues, low-privileged access.
  • Exploitation status: No confirmed exploitation reported in the collected data.
  • Remediation: Upgrade UniFi Protect to 7.2.105 or later and UniFi Access to 4.3.5 or later. Segment UniFi management infrastructure, restrict administrative roles, and investigate anomalous controller-to-device commands.

CVE-2026-82329 — JFrog Artifactory

  • Severity: CVSS 9.8
  • EPSS: Not available
  • Technical detail: An authentication weakness in Artifactory may allow an unauthenticated attacker with network access to obtain administrative privileges under default configuration. Affected branches include versions below 7.111.21, 7.161.20, 7.146.38, 7.125.20, 7.117.28, and 7.133.29, as applicable. Compromise could provide control over repositories, build artifacts, credentials, and software-delivery workflows.
  • Exploitation status: No confirmed exploitation reported in the collected data. This is distinct from the previously reported CVE-2026-66384 Artifactory path-traversal issue, which remains actively exploited.
  • Remediation: Apply the vendor’s fixed release for the deployed branch immediately. Disable or restrict unauthenticated access, review administrator creation and authentication logs, audit repository and artifact changes, and rotate credentials if compromise is suspected.

CVE-2026-55207 — Pimcore

  • Severity: CVSS 8.8
  • EPSS: 0.67 — high exploitation probability
  • Technical detail: An unauthenticated attacker may manipulate password-reset URL generation to take over administrator accounts and bypass two-factor authentication. Affected versions include Pimcore below 2025.4.6 and vulnerable 2026.1.x releases below 2026.1.6. Successful exploitation would provide administrative control of the content and data-management platform.
  • Exploitation status: No confirmed exploitation reported in the collected data.
  • Remediation: Upgrade to a fixed Pimcore release: 2025.4.6, 2026.1.6, 11.5.19, or 12.3.10 as applicable. Invalidate active sessions, reset administrator credentials, verify MFA enrollment, and review password-reset, authentication, and administrative-change logs.

CVE-2026-19286 / CVE-2026-19295 / CVE-2026-18729 — IBM Langflow OSS

  • Severity: CVSS 9.8–9.9
  • EPSS: 0.0 in the collected EUVD data; this does not indicate absence of future exploitation.
  • Technical detail: Langflow OSS versions 1.0.0 through 1.11.1 contain several code-execution issues. The reported weaknesses include unrestricted access to an A2A public endpoint, authenticated arbitrary code execution through crafted flows, and command execution via crafted type-field values. Exploitation could result in code execution within the server process and compromise of connected data or model services.
  • Exploitation status: No confirmed exploitation reported in the collected data.
  • Remediation: Upgrade Langflow OSS beyond 1.11.1 using the vendor’s fixed release guidance. Do not expose administrative or workflow endpoints directly to the internet; restrict access, review saved flows and endpoint activity, and inspect hosts for unauthorized processes or outbound connections.

ONGOING:

  • CVE-2026-8452 (Citrix NetScaler ADC/Gateway): Actively exploited; verify remediation and management-interface restrictions immediately.
  • CVE-2026-63520 (Microsoft SharePoint): Active exploitation and public PoC remain reported; patch and hunt for web shells.
  • CVE-2026-60004 (Gitea): KEV remediation deadline passed; patch immediately and audit Git hook directories.
  • CVE-2019-1068 (Microsoft SQL Server): Actively exploited; patch before the 2026-08-30 deadline.
  • CVE-2026-53362 (Linux Kernel): KEV-listed privilege escalation; patch before the 2026-08-30 deadline.
  • CVE-2023-49105 (ownCloud): Actively exploited; patch and configure signing keys before the 2026-08-30 deadline.
  • CVE-2026-19478 (GitLab): Actively exploited; upgrade to a fixed release.
  • CVE-2026-66384 (JFrog Artifactory): Actively exploited; patch and audit repositories and Docker caches.

European Advisories

  • [WID-SEC-2026-3071](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3071) (vm2, NEW): Multiple vulnerabilities may allow code execution with service privileges, security-control bypass, data disclosure or manipulation, and denial of service. Update vm2 and review applications that process untrusted JavaScript.
  • [WID-SEC-2026-3077](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3077) (Redis, NEW): Vulnerabilities may enable security-control bypass, unauthorized data access, memory manipulation, and potentially code execution. Patch Redis and restrict administrative interfaces.
  • [WID-SEC-2026-3076](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3076) (Dovecot, NEW): Issues may expose information, permit data manipulation or security bypass, and cause denial of service. Apply current vendor or distribution updates.
  • [WID-SEC-2026-3068](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3068) (WatchGuard Firebox OS, NEW): Vulnerabilities may enable code execution, including with root privileges. Prioritize internet-facing appliances and restrict management access.
  • [WID-SEC-2026-3061](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3061) (cPanel/WHM, NEW): An authenticated remote attacker may execute code with administrator privileges. Apply cPanel fixes and review reseller and hosting-account activity.
  • [WID-SEC-2026-3060](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3060) (ServiceNow): Covered in Critical Vulnerabilities.
  • WID-SEC-2026-1104 (Microsoft Windows, UPDATE): Apply current Microsoft updates; assess exposed and privileged systems first.
  • WID-SEC-2023-2985 (ownCloud, UPDATE): Covered in Critical Vulnerabilities.

Active Threats and Campaigns

  • PaperCut NG/MF exploitation — STATUS CHANGE: PaperCut released a second emergency update after researchers identified bypasses affecting initial fixes for actively exploited vulnerabilities. Update supported NG/MF deployments using the latest vendor emergency release, restrict administrative interfaces, and review application, web, and authentication logs for unauthorized configuration changes or Java execution. Bleeping Computer
  • Gitea exploitation — STATUS CHANGE: More than 8,300 internet-exposed Gitea instances reportedly remain vulnerable to ongoing remote code-execution attacks. Bleeping Computer
  • Microsoft 365 phishing campaigns — ONGOING: NovaCookies and Mirage2FA remain relevant; hunt for session-token theft, anomalous OAuth activity, unfamiliar session origins, and conditional-access changes.
  • Internet-exposed edge systems — ONGOING: Maintain external attack-surface monitoring and prioritize rapid remediation of exposed appliances.

Security News and Context

  • Berlin’s state administration confirmed an extortion attempt and additional data outflows after compromise of its administrative network. The Hacker News
  • APT28-linked campaigns targeting Romanian, Spanish, and Turkish government and diplomatic organizations reportedly deployed the HOOKEDGE backdoor. Validate detections for script-based Windows persistence and unusual outbound connections. The Hacker News
  • Researchers reported factory backdoors in ZBT OEM router firmware, providing unauthenticated root access. Heise Security
  1. Patch all exposed Ubiquiti UniFi Talk, Protect, and Access deployments; restrict management-plane access.
  2. Upgrade JFrog Artifactory and investigate for unauthorized administrative or repository changes.
  3. Patch Pimcore and invalidate administrator sessions and password-reset tokens.
  4. Upgrade IBM Langflow OSS and isolate workflow and A2A endpoints.
  5. Apply the second PaperCut emergency update and conduct targeted compromise review.
  6. Patch Gitea immediately and prioritize all internet-exposed instances.
  7. Complete ownCloud and Linux Kernel remediation before the 2026-08-30 KEV deadlines.
  8. Continue remediation of previously reported items: CVE-2026-8452, CVE-2026-63520, CVE-2019-1068, CVE-2026-19478, and CVE-2026-66384.