critical CVE-2026-78997
UC Browser for Android (package com.UCMobile.intl: Cross-site scripting possible
NVD (NIST) reports one vulnerability in UC Browser for Android (package com.UCMobile.intl with severity critical. The stated impact is cross-site scripting. Affected: CVE-2026-78997. The full description, affected versions and recommended action are available from NVD (NIST).
- CVSS
- 9.3
What this means for you
Attackers can run code in your users' browsers. This mainly affects publicly reachable portals and login forms, where sessions can be taken over.
Original source
Insights
More articles
Weekly situation, week 39: 83 advisories, 22 critical
Between 20 Sep and 27 Sep 2026 our sources recorded 83 advisories: 22 critical, 61 high.
Weekly situation, week 38: 108 advisories, 26 critical
Between 13 Sep and 20 Sep 2026 our sources recorded 108 advisories: 26 critical, 82 high.
Weekly situation, week 37: 117 advisories, 24 critical
Between 6 Sep and 13 Sep 2026 our sources recorded 117 advisories: 24 critical, 93 high.
Contact
Reputation takes years. Destruction takes seconds.
Talk to us before somebody else does. The first conversation is free and we reply the same business day.