CVE-2026-77549EPSS p41.6%
CVE-2026-77549CVE-2026-77549
Description
A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.
Scoring
| CVSS | 9.0 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 0.51% probability of exploitation · percentile 41.6% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-28 |