AI analysis
CVE-2026-77537 is an Improper Input Validation flaw (CWE-20) in Ubiquiti's UniFi Protect Application that allows a command injection against the host device. It is triggered by attacker-controlled input submitted over the network to the Protect application, and the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C) indicates no authentication, user interaction, or special conditions are required. A successful exploit yields code execution on the console hosting Protect, with critical confidentiality, integrity, and availability impact across the scope-changed host environment. Any organization or user running UniFi Protect — typically on a UniFi OS console that hosts the surveillance application — is potentially affected. There is no evidence of exploitation in the wild and no known public proof-of-concept; EPSS assigns a 0.9% probability of exploitation within 30 days, and vendor advisories report that fixes have shipped across the UniFi line.
What to do: Update the UniFi Protect Application and UniFi OS console firmware to the latest patched releases via the console's built-in update mechanism, as vendor advisories confirm the 10.0-rated fixes are available. Limit exposure by not publishing the Protect application directly to the internet and restricting which network segments can reach the console. Check console/application logs for unexpected commands or processes that would indicate exploitation attempts.
Affected
| Ubiquiti UniFi Protect Application | — |
Estimated exposure
large≈100,000+ Protect deployments (estimated), with likely only a subset internet-exposed — Ubiquiti has shipped millions of UniFi devices and Protect runs on widely deployed UniFi OS consoles (e.g., Dream Machine Pro, UNVR class) that are popular with SMB and prosumer self-hosted deployments, suggesting deployments in the…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.