CVE-2026-21639

Summary

A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product.

Affected Software

VendorProductVersion RangeStatus
Ubiquiti IncairMAX AC0 < 8.7.21affected
Ubiquiti IncairMAX M0 < 6.3.24affected
Ubiquiti IncairFiber AF60-XG0 < 1.2.3affected
Ubiquiti IncairFiber AF600 < 2.6.8affected

Weaknesses

  • CWE-120: CWE-120 Classic Buffer Overflow

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References