ZeroHour

CVE-2026-77537

large

Command Injection in Ubiquiti UniFi Protect Application

CVSS 3.1
10.0 critical
EPSS
<1%p59
Published
()
Modified
AI analysis

CVE-2026-77537 is an Improper Input Validation flaw (CWE-20) in Ubiquiti's UniFi Protect Application that allows a command injection against the host device. It is triggered by attacker-controlled input submitted over the network to the Protect application, and the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C) indicates no authentication, user interaction, or special conditions are required. A successful exploit yields code execution on the console hosting Protect, with critical confidentiality, integrity, and availability impact across the scope-changed host environment. Any organization or user running UniFi Protect — typically on a UniFi OS console that hosts the surveillance application — is potentially affected. There is no evidence of exploitation in the wild and no known public proof-of-concept; EPSS assigns a 0.9% probability of exploitation within 30 days, and vendor advisories report that fixes have shipped across the UniFi line.

What to do: Update the UniFi Protect Application and UniFi OS console firmware to the latest patched releases via the console's built-in update mechanism, as vendor advisories confirm the 10.0-rated fixes are available. Limit exposure by not publishing the Protect application directly to the internet and restricting which network segments can reach the console. Check console/application logs for unexpected commands or processes that would indicate exploitation attempts.

Affected
Ubiquiti UniFi Protect Application
Estimated exposure
large≈100,000+ Protect deployments (estimated), with likely only a subset internet-exposed — Ubiquiti has shipped millions of UniFi devices and Protect runs on widely deployed UniFi OS consoles (e.g., Dream Machine Pro, UNVR class) that are popular with SMB and prosumer self-hosted deployments, suggesting deployments in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.

Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

Three 10.0 security flaws fixed across Ubiquiti’s UniFi line

Ubiquiti patches 22 UniFi vulnerabilities, 21 rated critical including three CVSS 10.0 flaws enabling unauthorized access.

Ubiquiti disclosed and patched 22 vulnerabilities, 21 rated critical and three assigned the maximum CVSS 10.0 score: CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554. All three involve improper access control that could let attackers gain privileges, while other flaws permit authentication bypass or arbitrary command execution. All but one of the 22 affect the UniFi product line. The company did not confirm whether any were exploited before patching.