CVE-2026-77558
UniFi: Out-of-bounds Read (CVE-2026-77558)
highEPSS 0.5%
Description
A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
UbiquitiUniFi
Gateways <5.1.26Metrics
Show all metrics
Severity
high
79.01
no public PoC known
7.5
Published
2026-09-22 18:43 UTC
CWE-125
Weakness classes (CWE)
CWE-125Base
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-22 20:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-77558","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
- New CVE Received2026-09-22 19:16 UTC· fe490ce8-0395-4072-90d8-2707e1bdf984
- Description: A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CWE: CWE-125
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/77xxx/CVE-2026-77558.json">CVE-2026-77558</a>