Critical
Ubiquiti Warns of Max-Severity UniFi OS Vulnerability
Max severity
CVE-2026-50746Improper access control
Ubiquiti has released critical updates fixing seven severe vulnerabilities across UniFi OS. An attacker with network access can exploit CVE-2026-50746 to execute arbitrary commands on the host device. No confirmed in-the-wild exploitation yet, but Censys puts the exposed attack surface at over 100,000 internet-facing UniFi OS instances, about 50,000 of them in the US.
Critical
Pre-Auth Bypass in BeyondTrust Remote Access Tools
CVE-2026-40138CVE-2026-40139 CVSS 9.2
BeyondTrust has patched four vulnerabilities in its Remote Support and Privileged Remote Access on-premise appliances. Two let a remote, unauthenticated attacker bypass authentication entirely, including access to privileged accounts, contingent on a specific non-default configuration being enabled. RS and PRA sit behind remote support and privileged access for thousands of downstream MSP and ITSP client environments, so the blast radius extends well past the vendor itself.
Actively exploited
Citrix Bleed 2: Anubis Ransomware Actively Exploiting NetScaler
CVE-2025-5777 CVSS 9.3
"Citrix Bleed 2" is a critical authentication bypass in Citrix NetScaler ADC and Gateway, and it's under active exploitation. The out-of-bounds read flaw lets an unauthenticated attacker pull sensitive memory contents, including session tokens, off affected devices. Hijacked sessions bypass MFA and hand attackers initial network access.
Critical
WatchGuard Patches Critical RCE in Fireware OS and Mobile VPN Client
CVE-2026-13368 CVSS 9.2 Patched 2 Jul 2026
A race condition leading to use-after-free in IKEv2 LDAP authentication lets a remote, unauthenticated attacker execute arbitrary code on the firewall, provided Mobile VPN with IKEv2 is configured against an external LDAP server. A second, lower-severity flaw allows local privilege escalation on endpoints.