Junglewise Threat Intelligence

CVE-2026-77532: Ubiquiti EdgeMax EdgeSwitch buffer overflow in DHCPv6

CVE-2026-77532 · Severity: critical · CVSS 9.6 · Published 2026-08-26

Vendors: Ubiquiti.

Executive brief

A buffer overflow vulnerability in Ubiquiti's EdgeMax EdgeSwitch devices could allow an attacker on the adjacent network to execute arbitrary code with full control over the affected switch. This impacts network availability and could be used as an entry point to compromise the broader network infrastructure.

Technical details

A buffer overflow vulnerability exists in the DHCPv6 implementation of EdgeMax EdgeSwitch devices. An unauthenticated attacker with network adjacency (same local network segment) can send specially crafted DHCPv6 packets to trigger the overflow and achieve remote code execution (RCE). The vulnerability requires no user interaction or prior authentication. A patch is likely available through Ubiquiti's security advisories.

Affected products

  • Ubiquiti EdgeMax EdgeSwitch <UNKNOWN>

Timeline

  • 2026-08-26: disclosed
  • other: CVE-2026-77532 assigned

References