View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

Critical Microsoft UFO Flaw Enables Unauthenticated Android Device

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

๐Ÿ“‹ ADVISORIES

  • Composer flaw lets malicious PHP packages expose sensitive files CVE-2026-59944
    A Composer flaw lets malicious packages expose sensitive files.

    • PHP Composer users, especially shared-hosting, multi-tenant, CI/CD and build environments, are affected.
    • Composer 1.0โ€“2.2.29 and 2.3.0โ€“2.10.2 are vulnerable to CVE-2026-59944 and GHSA-96h3-5x6v-m776.
    • Malicious packages can use path traversal or symbolic links in declared binaries to target files outside their package directory.
    • Composer may change external files to world-readable and executable and register them under vendor/bin.
    • Tampered vendor/composer/installed.json metadata or reused vendor directories can bypass earlier path checks.
      ๐Ÿ“„ Source: github.com ยท ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News, cryptika.com (discovered)
  • Critical Microsoft UFO Flaw Enables Unauthenticated Android Device Control CVE-2026-73296
    A flaw in Microsoft UFO enables unauthenticated remote control of connected Android devices.

    • Microsoft UFO versions before 3.0.8 are affected when Mobile MCP services allow remote access.
    • CVE-2026-73296 has a CVSS score of 9.4 and exposes connected Android devices and emulators.
    • Missing authentication and authorization in mobile_mcp_server.py lets network clients invoke MCP requests.
    • The data and action servers use TCP ports 8020 and 8021 and can forward requests to ADB.
    • Attackers can capture screenshots, retrieve device details, tap, swipe, type text, launch apps, and send key events.
      ๐Ÿ“„ Source: github.com ยท ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News, cryptika.com (discovered)

๐Ÿ”“ CVEs & KEV

  • CVE-2026-58574 โ€” CVSS 9.8 โ€” Dell PowerStore contains a Missing Authentication for Critical Function vulne...

  • CVE-2026-68951 โ€” CVSS 6.9 โ€” GROWI contains an incorrect authorization vulnerability. If this vulnerabilit...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check