Sale of a 1-Day RCE Exploit for Ubiquiti UniFi Talk (CVE-2026-77554)

Dark Web2026-08-27, 12:03
For informational purposes only.
Vulnerability type: RCE Affected versions: UniFi Talk Application prior to 5.3.2
The seller claims to be offering a private exploit for CVE-2026-77554, a critical command injection vulnerability affecting the Ubiquiti UniFi Talk server application.
According to the seller, exploitation does not require prior authentication or any user interaction and allows an attacker to execute operating system commands on the host running the application.
As proof, the seller published screenshots showing tests of a private PoC. The seller claims the exploit works reliably against versions 5.3.1 and earlier and can result in full compromise of the affected host.
Ubiquiti disclosed the vulnerability in Security Advisory Bulletin 067. According to the vendor, the flaw is caused by improper input validation and allows an attacker with network access to the application to inject commands on the host device. The vulnerability received the maximum CVSS 3.1 score of 10.0.
UniFi Talk is Ubiquiti’s business VoIP platform for managing phone services, devices, users, phone numbers, and call routing through the UniFi ecosystem. The vulnerability affects the UniFi Talk application running on the host, rather than any specific IP phone model.
Ubiquiti has a large global installed base. The company reports cumulative shipments of nearly 85 million devices used in network deployments across more than 200 countries and territories.
The official UniFi Talk subscription is available in the United States, Canada, and the United Kingdom. Outside those markets, unlocked UniFi Talk phones can be used with third-party SIP providers, meaning the platform’s actual geographic footprint extends beyond the countries where the official subscription service is offered.
Vulnerabilities
10
CVE-2026-77554
Vendors
Ubiquiti
Products
Unifi Talk