Tech News

22 Vulnerabilities Fixed in the UniFi Ecosystem, Including 3 Rated CVSS 10/10

The security bulletin published on August 26, 2026 by Ubiquiti patches around twenty security flaws and casts a wide net across impacted products: UniFi Protect, UniFi Network, UniFi Access, UniFi Talk, UniFi Connect, UniFi OS. Most of the Ubiquiti ecosystem is affected, including 3 vulnerabilities rated CVSS 10 out of 10.

21 Critical Flaws Out of 22, and Three Top Scores

The security bulletin published by Ubiquiti lists a total of 22 vulnerabilities, and with just one exception, all the others are considered critical. The stage is set. As for the three flaws with a CVSS score of 10 out of 10, here they are:

  • CVE-2026-77537, in the UniFi Protect application. An input validation issue could allow an attacker on the network, with no specific privileges and no user interaction, to perform command injection on the host.
  • CVE-2026-77550, in UniFi OS. Incorrect neutralization of CRLF sequences could allow authentication bypass on UniFi OS devices and instances.
  • CVE-2026-77554, in the UniFi Talk application. Once again, host command injection from the network, without authentication.

Between command injection, privilege escalation, and authentication bypass, the vulnerabilities are varied. One of them is even rather unusual: CVE-2026-77545 (CVSS score of 9.0 out of 10). It corresponds to debug code that was accidentally left enabled in UniFi OS.

"A malicious actor with network access and who meets certain conditions could exploit a vulnerability related to incorrect neutralization of CRLF sequences, present in certain devices running UniFi OS, in order to bypass authentication on those UniFi OS devices or instances.", reads the description of CVE-2026-77549.

At this stage, Ubiquiti does not say whether these vulnerabilities were exploited before the fixes were released. But still, caution is warranted: Ubiquiti clearly states that the vulnerabilities are easily exploitable, and above all, require no user interaction.

The Patched Versions Released by Ubiquiti

For the patched versions, I invite you to consult Ubiquiti's security bulletin for all the details. Here is a summary of the minimum versions you should install on your devices and instances:

  • UniFi Protect Application : 7.2.105 (versions 7.1.87 and earlier are vulnerable)
  • UniFi Network Application : 10.5.67 (versions 10.4.57 and earlier)
  • UniFi Access Application : 4.3.5 (versions 4.3.3 and earlier)
  • UniFi Talk Application : 5.3.2 (versions 5.2.7 and earlier)
  • UniFi Connect Application : 3.24.22 (versions 3.24.20 and earlier)
  • UID Enterprise Agent : 1.62.1 (versions 1.61.8 and earlier)
  • UniFi OS Server : 5.1.37 (versions 5.1.21 and earlier)
  • UniFi Connect Display Cast Pro : 1.0.111,
  • UniFi Enterprise Audio/Video Bridge : 1.0.11,
  • UniFi Protect AI Key : 2.2.6

To motivate you to patch quickly, I want to come back to the previous security alert tied to the Ubiquiti ecosystem. On May 21, Ubiquiti had patched three security flaws in UniFi OS, and they were also rated 10 out of 10. A month later, on June 23, 2026, CISA added them to its catalog of actively exploited vulnerabilities. The story may not repeat itself, but given the density of this security bulletin, I have serious doubts.

At the same time, Ubiquiti equipment is a prime target for cybercriminals. This is even more true since there are reportedly more than 100,000 UniFi OS instances exposed to the Internet, according to Censys analysis. That number should be taken with a grain of salt, but it does show a trend.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.