CVE-2026-77550
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 10epss 0.5%
exploitation probability
0.5%top 60% of all CVEs
observed exploitation
nono source reports it
A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
Ubiquiti Inc · Cloud GatewaysUbiquiti Inc · Cloud KeysUbiquiti Inc · Dream MachinesUbiquiti Inc · Dream RoutersUbiquiti Inc · Dream WallUbiquiti Inc · Enterprise Firewall CoreUbiquiti Inc · Enterprise Fortress GatewayUbiquiti Inc · Enterprise Network Attached StorageUbiquiti Inc · Enterprise Network Video RecordersUbiquiti Inc · ExpressUbiquiti Inc · Express 7Ubiquiti Inc · Network Attached StorageUbiquiti Inc · Network Video RecordersUbiquiti Inc · UniFi OS Server