<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cve-2026-22557 — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-22557/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata — refreshed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 21 Mar 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-22557/feed.xml" rel="self" type="application/rss+xml"/><item><title>UniFi Network Application Vulnerabilities CVE-2026-22557 and CVE-2026-22558</title><link>https://feed.craftedsignal.io/briefs/2026-03-unifi-vulns/</link><pubDate>Sat, 21 Mar 2026 12:00:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-03-unifi-vulns/</guid><description>A combination of path traversal (CVE-2026-22557) and NoSQL injection (CVE-2026-22558) vulnerabilities in the UniFi Network Application allows attackers to access files, escalate privileges, and potentially compromise the entire system.</description><content:encoded>&lt;p>The UniFi Network Application, a central platform for managing network devices across enterprise and SMB environments, is affected by two critical vulnerabilities: CVE-2026-22557 (Path Traversal) and CVE-2026-22558 (Authenticated NoSQL Injection). These vulnerabilities impact Official Release versions 10.1.85 and earlier, Release Candidate versions 10.2.93 and earlier, and UniFi Express (UX) versions 9.0.114 and earlier. Exploitation of CVE-2026-22557 enables attackers to access and manipulate…&lt;/p>
</content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>unifi</category><category>path-traversal</category><category>nosql-injection</category><category>cve-2026-22557</category><category>cve-2026-22558</category></item></channel></rss>