ZeroHour

CVE-2026-34910

KEV PoC mass

Unauthenticated Command Injection in Ubiquiti UniFi OS Devices

CISA: Ubiquiti UniFi OS Improper Input Validation Vulnerability

CVSS 3.1
10.0 critical
EPSS
87%p100
Published
()
KEV added
AI analysis

CVE-2026-34910 is an improper input validation flaw (CWE-20) in Ubiquiti UniFi OS that allows command injection on affected gateways and network video recorders. A malicious actor with network access to the device can send crafted, unvalidated input that triggers arbitrary command execution, with no privileges or user interaction required (CVSS 3.1 base score 10.0, network vector, scope changed). Successful exploitation grants full control of the device — high confidentiality, integrity, and availability impact — and can serve as a foothold into the attached network. Affected products span the UniFi gateway and recording line: UniFi OS Server, Cloud Gateway Industrial, Dream Machine/Pro/Special Edition/Pro Max, Enterprise Fortress Gateway, Dream Wall, Dream Router and Dream Router 7, UniFi Express 7, and the UniFi Network Video Recorder. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-06-23, public reporting describes in-the-wild exploitation being used to build a Mirai botnet, and EPSS estimates an 87.5% chance of exploitation within 30 days.

What to do: Upgrade all listed UniFi OS devices to the fixed firmware in Ubiquiti's June 2026 security advisory (consult the vendor advisory for exact fixed versions per product), and per CISA BOD 26-04 patch within the required window or discontinue use of affected cloud-reachable assets. Restrict device management interfaces (UniFi Network UI, SSH, API) to trusted networks and audit internet-facing gateways for signs of compromise, including Mirai botnet traffic or unexpected outbound connections.

Affected
Ubiquiti (ui) UniFi OS
Ubiquiti (ui) UniFi OS Server
Ubiquiti (ui) UniFi Cloud Gateway Industrial firmware
Ubiquiti (ui) UniFi Dream Machine firmware
Ubiquiti (ui) UniFi Dream Machine Pro firmware
Ubiquiti (ui) UniFi Dream Machine Special Edition firmware
Ubiquiti (ui) UniFi Dream Machine Pro Max firmware
Ubiquiti (ui) Enterprise Fortress Gateway firmware
Ubiquiti (ui) UniFi Dream Wall firmware
Ubiquiti (ui) UniFi Dream Router firmware
Ubiquiti (ui) UniFi Dream Router 7 firmware
Ubiquiti (ui) UniFi Express 7 firmware
Estimated exposure
mass≈1M+ UniFi gateways/NVRs deployed worldwide, with on the order of hundreds of thousands internet-exposed — Ubiquiti's UniFi gateway and NVR line is one of the most widely deployed SMB/prosumer networking platforms with millions of installed devices, and public internet scans routinely show hundreds of thousands of UniFi devices reachable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

CISA Known Exploited Vulnerability
Affected
Ubiquiti UniFi OS
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Due date
Ransomware use
Unknown
Vendors
ui
Products
unifi os server, unifi cloud gateway industrial firmware, unifi dream machine firmware, unifi dream machine pro firmware, unifi dream machine special edition firmware, unifi dream machine pro max firmware, enterprise fortress gateway firmware, unifi dream wall firmware, unifi dream router firmware, unifi dream router 7 firmware, unifi express 7 firmware, unifi network video recorder firmware
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

CVE-2026-34908, CVE-2026-34909, CVE-2026-34910: Ubiquiti UniFi OS ...

Ubiquiti UniFi OS flaws CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 were added to CISA's KEV, chaining auth bypass into command injection.

Ubiquiti UniFi OS vulnerabilities CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 were added to CISA's KEV catalog. CVE-2026-34908 (CVSS 10.0, CWE-284) is an unauthenticated improper access control flaw allowing unauthorized system changes, described as the initial entry point. It enables attackers to then leverage chained path traversal and command injection flaws for deeper compromise.