CVE-2026-73296Disclosure

MEDIUMCVSS 9.4 · CRITICAL

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports 8020 and 8021 without authentication, allowing an unauthenticated remote attacker to invoke capture_screenshot, get_ui_tree, tap, swipe, type_text, launch_app, press_key, and click_control against an ADB-connected Android device, disclose screen and device data, and modify device state. This issue is fixed in version 3.0.8.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-862

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 5 mentions (2026-08-31); latest day: 1
  • 9 total mentions across 4 days

Deep dive

Activity timeline9 mentions / 4d
01345Mentions · 2026-08-12: 1Mentions · 2026-08-31: 5Mentions · 2026-09-01: 2Mentions · 2026-09-03: 1PoC Mentioned / Linked · 2026-08-31: 1Active Exploitation · 2026-08-31: 1Patch / Workaround · 2026-08-31: 3Patch / Workaround · 2026-09-01: 2Technical Details · 2026-08-31: 5Technical Details · 2026-09-01: 208-1208-3109-0109-03
Signal classification4 categories
Disclosure
666.7%
General
111.1%
Active Exploitation
111.1%
Patch
111.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-08-121
General1
2026-08-315
Active Exploitation1Disclosure3Patch1
2026-09-012
Disclosure2
2026-09-031
Disclosure1
Full discourse9 posts
  • ɐpnH@AlAssaf_H
    Disclosure

    CVE-2026-73296 : Microsoft UFO Mobile MCP exposes ADB-backed Android functionality without authentication in versions ≤ v3.0.7. The default bind is localhost, but the documented remote configuration exposes the MCP services on 0.0.0.0:8020/8021. Any network client that can reach them can initialize an MCP session → capture screenshots and UI data → enumerate apps/device state → inject taps, swipes, text and key events → launch apps. No API key, authenticated UFO session, model cooperation, browser interaction, or user approval required. Trust boundary: reachable network → unauthenticated MCP → ADB-connected Android device. Critical — CVSS 9.4: https://github.com/microsoft/UFO/security/advisories/GHSA-24fq-m9rr-g3mm

    Post summary

    The post discloses CVE-2026-73296 as an unauthenticated remote ADB vulnerability in Microsoft UFO Mobile MCP, providing technical exploitation details and a high CVSS score, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    26025121.9K
    852 followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Patch

    🔴 Microsoft UFO framework’ünde kritik güvenlik açığı! Microsoft’un açık kaynaklı UFO otomasyon framework’ünde keşfedilen CVE-2026-73296 (CVSS 9.4), uzaktan erişime açılmış Mobile MCP servislerinde kimlik doğrulama olmaması nedeniyle saldırganların ADB’ye bağlı Android cihazları uzaktan görüntülemesine ve kontrol etmesine neden olabiliyor. Etkilenen sürümler: UFO < 3.0.8 Saldırganlar; • Ekran görüntülerini alabilir • Kurulu uygulama ve cihaz bilgilerini görebilir • Ekrana dokunabilir ve kaydırma yapabilir • Metin girebilir • Uygulama başlatabilir • Android üzerinde çeşitli ADB işlemleri gerçekleştirebilir Açık, özellikle Mobile MCP servislerinin 0.0.0.0 üzerinden internete/harici ağlara açıldığı yapılandırmalarda kritik hale geliyor. Çözüm: UFO’yu 3.0.8 veya üzeri sürüme güncelleyin. Ayrıca 8020 ve 8021 numaralı portların dışarıdan erişilebilir olup olmadığını kontrol edin.

    Post summary

    The post announces a high‑severity vulnerability in Microsoft UFO and provides patch guidance, making patch discussion the main focus.

    01074624
    2.3K followersView on X
  • Bussio28Team | Ciberseguridad sin humo@Bussio28Team
    Disclosure

    CVE-2026-73296 merece atención: afecta a Microsoft UFO y puede permitir controlar dispositivos Android vía ADB si los servicios MCP quedan expuestos sin autenticación. CVSS 9.4. Si usas UFO, revisa ya los puertos 8020/8021 y evita exponerlos a Internet. Te lo explico en https://bussio28team.es/2026/08/31/cve-2026-73296-microsoft-ufo-android-adb/ #Ciberseguridad #vuln

    Post summary

    The post announces CVE‑2026‑73296, a high‑severity flaw in Microsoft UFO that can let attackers gain control of Android devices through ADB when MCP services are unauthenticated, and urges users to block ports 8020/8021.

    04030124
    923 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    CVSS 9.4 vulnerability discovered in Microsoft's open-source UFO automation framework. Info, incl. fix info, now at SecAlerts: CVE-2026-73296, CVSS 9.4 - https://secalerts.co/vulnerability/CVE-2026-73296 #ciso #cio #cto #vulnerabilities #cybersecurity #msp #mssp #secalerts #CVE202673296 #Microsoft https://t.co/fiJQqdGMLn

    Post summary

    A CVE‑2026‑73296 vulnerability with CVSS 9.4 was discovered in Microsoft's UFO automation framework, and fix information is available on SecAlerts.

    00011157
    885 followersView on X
  • The Daily Tech Feed@dailytechonx
    Disclosure

    Urgent security alert: Microsoft UFO’s CVE-2026-73296 flaw allows remote attackers full control over Android devices without login or interaction. Vulnerable before v3.0.8, when MCP services exposed over HTTP. High risk of data exposure, UI control, app launches — zero auth needed. Upgrade now, restrict ports 8020/8021, bind services to localhost or use secure proxies. #Microsoft #Security #UFO #Android #Vulnerability #CyberSecurity https://thedailytechfeed.com/microsoft-ufo-vulnerability-exposes-android-devices-to-remote-control/

    Post summary

    The post announces Microsoft UFO CVE‑2026‑73296 as a high‑risk flaw permitting remote control of Android devices without authentication, providing technical details and remediation advice, but no exploit code or evidence of current exploitation.

    0001074
    691 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    Microsoft UFOのMobile MCPにCVE-2026-73296 認証なしでAndroid端末を遠隔操作されるおそれ https://rocket-boys.co.jp/security-measures-lab/microsoft-ufo-mcp-cve-2026-73296-android/ #セキュリティ対策Lab #security #securitynews #セキュリティ

    Post summary

    The article announces CVE-2026-73296, highlighting a vulnerability in Microsoft UFO Mobile MCP that could allow unauthenticated remote control of Android devices, but offers no PoC, exploit details, mitigation, or evidence of active exploitation.

    00000148
    624 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Microsoft UFO Unauth Remote Control via Exposed Streamable HTTP MCP (CVE-2026-73296) Microsoft UFO mobile MCP server exposes Streamable HTTP MCP services on TCP 8020/8021 with no authentication. Remote attackers can invoke MCP actions (screenshot, UI tree, taps/swipes/typing/app launch) to exfiltrate screen/device data and control an ADB-connected Android device. 👉Affected: microsoft/UFO < 3.0.8 | Upgrade to 3.0.8

    Post summary

    A critical unauthenticated remote control vulnerability (CVE-2026-73296) in Microsoft UFO's streamable HTTP MCP services is disclosed, affecting versions below 3.0.8, with remediation via upgrading to 3.0.8.

    00000125
    296 followersView on X
  • SDTEK@SDTEK
    Active Exploitation

    Microsoft’s AI agent OS (UFO) has a critical flaw (CVE-2026-73296, CVSS 9.4) — attackers on the same network can silently read your employees’ OTPs, messages, and screen, and type commands on their phones. No password needed. No patch yet. #cybersecurity #AI #MSP

    Post summary

    CVE-2026-73296 is a critical flaw in Microsoft’s AI agent OS that allows attackers on the same network to silently read OTPs, messages, and screen data, and to type commands on target phones, with no patch available yet.

    0000049
    698 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-73296 Microsoft UFO Unauthenticated Remote Control of Android Devices v... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-73296 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet merely references CVE-2026-73296 with a link to a vulnerability detail page, offering no additional technical, exploit, or mitigation information.

    00000105
    4.1K followersView on X

Explore more