Three maximum-severity vulnerabilities have been disclosed in Ubiquiti’s UniFi network products, all exploitable remotely without authentication. Separately, CISA has confirmed active exploitation of a critical code injection flaw in Gitea, the self-hosted Git service widely used for internal code repositories. Both disclosures highlight a persistent gap in how UK businesses secure infrastructure that sits behind the public perimeter. UniFi kit manages internal networks and physical security systems across thousands of SMBs, yet firmware updates often lag months behind current versions. Gitea servers hold development code, credentials, and API keys, but are frequently treated as lower-priority assets despite their access to production environments. The observed Gitea exploitation involves cryptominer deployment, but the real risk is remote code execution on systems that touch sensitive infrastructure. This episode examines why trusted infrastructure receives less scrutiny than customer-facing systems, and why that gap creates exploitable exposure. Mauven provides specific patch guidance, incident response steps, and asset inventory priorities for both vulnerabilities.