CVE-2026-21639: UI Airfiber AF60-XG Firmware

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product.

Affected products

  • UI Airfiber AF60-XG Firmware: before 1.2.3 (fixed in 1.2.3)
  • UI Airfiber AF60 Firmware: before 2.6.8 (fixed in 2.6.8)
  • UI Airmax Ac Firmware: before 8.7.21 (fixed in 8.7.21)
  • UI Airmax M Firmware: before 6.3.24 (fixed in 6.3.24)

Published 2026-01-08. Last modified 2026-07-30.