Microsoft
Microsoft UFO: vulnerabilidades y CVE
Microsoft UFO tiene 11 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses11
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-62316 | Alta (8.8) | 0.51% | — | 21 ago 2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but… |
| CVE-2026-73297 | Media (6.9) | 2.9% | — | 12 ago 2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked_ip in ufo/utils/url_security.py did not block NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48, the… |
| CVE-2026-73296 | Crítica (9.4) | 3.7% | — | 12 ago 2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in… |
| CVE-2026-55440 | Media (6.5) | 1.3% | — | 16 jul 2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/server/ws/handler.py called get_or_create_session in… |
| CVE-2026-54568 | Media (4.3) | 0.98% | — | 16 jul 2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a client connected to the UFO WebSocket server as a DEVICE could call DEVICE_INFO_REQUEST with another… |
| CVE-2026-46544 | Media (5.3) | 0.67% | — | 27 may 2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO accepts client-supplied session_id values in WebSocket task messages and reuses an… |
| CVE-2026-46538 | Media (5.9) | 0.29% | — | 27 may 2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's constellation client tracks pending task responses by session_id only and does not… |
| CVE-2026-46416 | Media (6.3) | 0.45% | — | 27 may 2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO creates one shared UFOWebSocketHandler instance and reuses it for multiple authenticated… |
| CVE-2026-46414 | Alta (8.8) | 0.85% | — | 27 may 2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's WebSocket control plane trusts client-supplied identity and role fields in task… |
| CVE-2026-46402 | Alta (8.1) | 1.0% | — | 27 may 2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO uses the user-controlled task_name value directly when constructing session log paths. An… |
| CVE-2026-45322 | Alta (7.8) | 2.1% | — | 27 may 2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. Microsoft UFO tagged releases up to and including v3.0.0 contain an OS command injection vulnerability in the shell action… |