AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-73296

CRITICAL · CVSS 9.4 EPSS 2.61% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Microsoft UFO framework prior to version 3.0.8 is vulnerable due to exposed Streamable HTTP MCP services on TCP ports 8020 and 8021, which lack authentication. This allows unauthenticated remote attackers to execute various commands on ADB-connected Android devices, potentially disclosing sensitive screen and device data and altering device states. Organizations utilizing this framework, particularly those managing Android devices, should prioritize upgrading to version 3.0.8 to mitigate this critical risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73296
Severity
CRITICAL
CVSS
9.4
EPSS
2.61%
Microsoft Android

Original NVD Description

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports 8020 and 8021 without authentication, allowing an unauthenticated remote attacker to invoke capture_screenshot, get_ui_tree, tap, swipe, type_text, launch_app, press_key, and click_control against an ADB-connected Android device, disclose screen and device data, and modify device state. This issue is fixed in version 3.0.8.