critical CVE-2026-78997
UC Browser for Android (package com.UCMobile.intl: Cross-site scripting possible
NVD (NIST) reports one vulnerability in UC Browser for Android (package com.UCMobile.intl with severity critical. The stated impact is cross-site scripting. Affected: CVE-2026-78997. The full description, affected versions and recommended action are available from NVD (NIST).
- CVSS
- 9.3
What this means for you
Attackers can run code in your users' browsers. This mainly affects publicly reachable portals and login forms, where sessions can be taken over.
Original source
Insights
More articles
Weekly situation, week 36: 55 advisories, 12 critical
Between 30 Aug and 6 Sep 2026 our sources recorded 55 advisories: 12 critical, 43 high.
Weekly situation, week 35: 75 advisories, 21 critical
Between 23 Aug and 30 Aug 2026 our sources recorded 75 advisories: 21 critical, 54 high.
Weekly situation, week 34: 91 advisories, 9 critical
Between 16 Aug and 23 Aug 2026 our sources recorded 91 advisories: 9 critical, 82 high.
Contact
Reputation takes years. Destruction takes seconds.
Talk to us before somebody else does. The first conversation is free and we reply the same business day.