ZeroHour
Vendor

Ubiquiti

1 mentions in 7 days · 10 in 30 days · 10 total · first seen · last

Timeline

Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF

AI-orchestrated campaign exploited PaperCut NG/MF RCE (CVE-2026-81578/82078), compromising 440+ instances at 395 organizations in 48 countries.

GreyNoise tracked a likely Russian-speaking actor using AI (OpenAI Codex harness plus a DeepSeek model) to develop, test, and deploy exploits for PaperCut NG/MF (CVE-2026-81578, CVE-2026-82078) starting 31 August 2026. The actor compromised at least 440 PaperCut instances across 395 organizations in 48 countries, achieving domain admin at 12 victims — fastest time to domain admin was five minutes and a US high school was fully compromised in seven minutes. Attack paths involved LSASS memory and registry secret harvesting, pass-the-hash to domain controllers, noPac attacks, account additions to Domain Admins, and DCSync to exfiltrate full NTDS.DIT credential dumps. Impact scope suggests access development potentially for handoff, with prior PaperCut intrusions historically leading to extortion.

GreyNoiseupdated · 4d agofirst · 6d agoThreat actor in the wild 9 sourcesCVE-2026-81578CVE-2026-82078CVE-2021-42278+1 CVEs1

CVE-2026-34908: UniFi OS Auth Bypass Vulnerability

Ubiquiti disclosed CVE-2026-34908, a CVSS 10.0 authentication bypass in UniFi OS letting network-adjacent attackers alter device configuration without credentials.

CVE-2026-34908 is an improper access control flaw (CWE-284) in Ubiquiti UniFi OS devices, disclosed in UI Security Advisory Bulletin 064, with a CVSS 3.1 base score of 10.0. An unauthenticated network-adjacent attacker can bypass access controls and modify system configuration, with scope-changed impact on downstream network services such as routing, VPN, and connected access points. Fixed firmware is available, and workarounds include restricting management ports to trusted subnets, isolating management interfaces on a dedicated VLAN, and disabling remote access features. No public proof-of-concept code was observed at the time of publication.

CVE-2026-34908: Ubiquiti Networks UniFi OS Server access control ...

CVE-2026-34908, a CVSS 10.0 access-control bypass in Ubiquiti UniFi OS, was added to CISA's KEV catalog amid reported active exploitation.

CISA added CVE-2026-34908 to the Known Exploited Vulnerabilities catalog on June 23, 2026, with remediation due June 26 under BOD 26-04 guidance. The CVSS 10.0 improper access control flaw (CWE-284) in Ubiquiti UniFi OS allows unauthorized system changes without authentication. Multiple news reports referenced by the page describe the max-severity UniFi flaws being exploited in attacks, and an official patch is available.

404 Media

404 Media homepage roundup: WordPress CEO Matt Mullenweg put on leave, first Take It Down Act sentence of 15 years, and DHS predictive policing revelations.

The 404 Media feed aggregates stories including Automattic board members voting WordPress co-founder Matt Mullenweg onto a leave of absence, and James Strahler receiving 15 years under the Take It Down Act for real and AI-generated sexually explicit images plus threats. It also reports a secretive DHS Border Patrol predictive policing unit that analyzes Americans' financial data and has local police pull people over with no suspected crime. Additional items cover Channel 5 sharing subscriber emails with Hunter Biden despite its privacy policy, and a man's death after emotional reliance on ChatGPT.

404 Media · 7d agoOther

Weekly Update 520: The Unscripted Edition

Troy Hunt's Weekly Update 520 covers YouTube's automatic thumbnail generation and installing a Lockwood ES2100 electric strike with Ubiquiti Access door locking.

Troy Hunt's Weekly Update 520 is a personal vlog post with no security news content. He experimented with YouTube's automatic 'create video thumbnail' feature to replace manual Photoshop work. He also installed a Lockwood ES2100 electric strike with a built-in door position sensor on his first fully installed Ubiquiti Access door lock, planning a full review after upcoming travel.

Troy Hunt · 8d agoOther

Weekly Update 519: Breaches & Data Integrity

Troy Hunt's weekly update mentions new breach data dumps, IoT door lock research, and conference preparations.

Troy Hunt's Weekly Update 519 notes that attackers have again dumped more stolen data, and discusses ongoing work including IoT door lock testing and mapping network hardware in Ubiquiti's design tool. It also references upcoming talks in Oslo and Copenhagen. The post is a routine personal update with no new vulnerability, breach details, or research findings.

Troy Hunt · 14d agoIndustry

CVE-2026-34908, CVE-2026-34909, CVE-2026-34910: Ubiquiti UniFi OS ...

Ubiquiti UniFi OS flaws CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 were added to CISA's KEV, chaining auth bypass into command injection.

Ubiquiti UniFi OS vulnerabilities CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 were added to CISA's KEV catalog. CVE-2026-34908 (CVSS 10.0, CWE-284) is an unauthenticated improper access control flaw allowing unauthorized system changes, described as the initial entry point. It enables attackers to then leverage chained path traversal and command injection flaws for deeper compromise.

Three 10.0 security flaws fixed across Ubiquiti’s UniFi line

Ubiquiti patches 22 UniFi vulnerabilities, 21 rated critical including three CVSS 10.0 flaws enabling unauthorized access.

Ubiquiti disclosed and patched 22 vulnerabilities, 21 rated critical and three assigned the maximum CVSS 10.0 score: CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554. All three involve improper access control that could let attackers gain privileges, while other flaws permit authentication bypass or arbitrary command execution. All but one of the 22 affect the UniFi product line. The company did not confirm whether any were exploited before patching.

Ubiquiti security advisory (AV26-850)

Canada's Cyber Centre reports critical vulnerabilities across Ubiquiti UniFi products including UniFi OS Server, Network, Protect, and Access; updates required.

The Canadian Centre for Cyber Security (AV26-850) reports critical vulnerabilities affecting numerous Ubiquiti products, including UniFi OS Server (<=5.1.21), UniFi Network Application (<=10.4.57), UniFi Protect Application (<=7.1.87), and UniFi Access Application (<=4.3.3). Other affected products include UniFi Connect, UID Enterprise Agent, UniFi Talk, UniFi Protect AI Key, Connect Display Cast Pro, and Enterprise Audio/Video Bridge. Administrators should update affected applications and devices; the advisory lists no CVE ids or exploitation details.

Canadian Centre for Cyber Security · 20d agoAdvisory

Weekly Update 518: IoT Doorlock Nirvana with UniFi

Troy Hunt describes building a home IoT door-lock setup around Ubiquiti UniFi hardware, relying on main power rather than batteries.

In Weekly Update 518, Troy Hunt describes integrating Ubiquiti UniFi smart door locks into his home, calling the result IoT door-lock nirvana. He highlights basic tenets such as powering the locks from main power rather than relying on batteries.

Troy Hunt · 22d agoOther

Related CVEs

  • Improper Access Control in Ubiquiti UniFi OS Devices (CVE-2026-34908)
    CVE-2026-34908 is an improper access control flaw (CWE-284) in Ubiquiti UniFi OS, the operating system running on UniFi gateways, Dream Machine appliances, and UniFi network video recorders. An attacker who can reach the device over the network — with no privileges or user interaction required per the CVSS vector — can make unauthorized changes to the system. The CVSS 3.1 score of 10.0 with a changed scope (S:C) indicates a successful attack can compromise the device beyond its intended security boundary, with high impact to confidentiality, integrity, and availability. Any organization running the affected UniFi OS products, including UniFi OS Server and the Dream Machine, Cloud Gateway, Enterprise Fortress, Dream Router, Express, and UNVR lines, is affected; specific vulnerable and fixed firmware versions are not specified in the available data. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-06-23, confirming active exploitation, and EPSS assigns an 85.2% probability of exploitation within 30 days (100th percentile); ransomware use is unknown.
    · Ubiquiti UniFi OS Server · Ubiquiti UniFi Cloud Gateway Industrial firmware KEV PoC mass
  • Unauthenticated Path Traversal in Ubiquiti UniFi OS Devices
    A path traversal flaw (CWE-22) in Ubiquiti UniFi OS, carrying a maximum CVSS 3.1 score of 10.0, allows a malicious actor with network access to send crafted requests that traverse directories and read arbitrary files on the underlying system. Files retrieved this way can be manipulated to gain access to an underlying account, and the CVSS vector's scope-changed, high-impact ratings indicate the resulting compromise can extend beyond the vulnerable component. Any environment running the affected UniFi OS devices is at risk, spanning UniFi OS Server and the Dream Machine, Dream Router, Dream Wall, Cloud Gateway, Enterprise Fortress Gateway, UniFi Express 7, and UniFi Network Video Recorder firmware families. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-06-23, confirming exploitation in the wild, and EPSS assigns a 63.9% probability of exploitation within 30 days (99th percentile). It was patched by Ubiquiti in June 2026 alongside related UniFi OS issues CVE-2026-34908 and CVE-2026-34910.
    · Ubiquiti UniFi OS Server · Ubiquiti UniFi Cloud Gateway Industrial firmware KEV PoC mass
  • Unauthenticated Command Injection in Ubiquiti UniFi OS Devices
    CVE-2026-34910 is an improper input validation flaw (CWE-20) in Ubiquiti UniFi OS that allows command injection on affected gateways and network video recorders. A malicious actor with network access to the device can send crafted, unvalidated input that triggers arbitrary command execution, with no privileges or user interaction required (CVSS 3.1 base score 10.0, network vector, scope changed). Successful exploitation grants full control of the device — high confidentiality, integrity, and availability impact — and can serve as a foothold into the attached network. Affected products span the UniFi gateway and recording line: UniFi OS Server, Cloud Gateway Industrial, Dream Machine/Pro/Special Edition/Pro Max, Enterprise Fortress Gateway, Dream Wall, Dream Router and Dream Router 7, UniFi Express 7, and the UniFi Network Video Recorder. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-06-23, public reporting describes in-the-wild exploitation being used to build a Mirai botnet, and EPSS estimates an 87.5% chance of exploitation within 30 days.
    · Ubiquiti (ui) UniFi OS · Ubiquiti (ui) UniFi OS Server KEV PoC mass
  • Unsafe Reflection RCE in PaperCut NG/MF, Chained with Auth Bypass in Attacks
    CVE-2026-82078 is an unsafe dynamic class loading flaw (unsafe reflection, CWE-470) in the database connection utilities of PaperCut NG and PaperCut MF: the software instantiates a database driver class based on a configurable driver name without validating it against an allowlist of approved drivers. An attacker who can manipulate system configuration parameters can point that setting at classes of their choosing, causing the server to execute arbitrary Java bytecode residing on the application classpath in the security context of the PaperCut server process. On its own the issue is rated 9.4 (Critical) with high privileges required, but when chained with the companion authentication bypass CVE-2026-81578 it yields unauthenticated remote code execution on the print-management server. All PaperCut NG and MF deployments are in scope; affected version ranges were not specified in the available data, so administrators should consult PaperCut's advisory for fixed versions. The flaw is confirmed exploited in the wild as a zero-day: it was added to CISA's KEV catalog on 2026-08-31, and public reporting describes an AI-orchestrated campaign that compromised PaperCut servers at roughly 395 organizations (~440 servers), with EPSS currently at 1.7% (76th percentile).
    · PaperCut NG · PaperCut MF KEVmass
  • Missing Authentication for Critical Function in PaperCut NG/MF Web Interface
    CVE-2026-81578 is an improper access control flaw (CWE-305) in the web management interface of PaperCut MF and PaperCut NG in which administrative requests from unauthenticated remote users trigger backend actions before access validation completes. An attacker can invoke administrative functions without logging in, allowing modification of certain system configurations. When chained with CVE-2026-82078 (unsafe dynamic class loading), the flaw has been used to achieve unauthenticated code execution. Any organization running PaperCut NG/MF, particularly servers whose web management interface is reachable from the internet or untrusted networks, is affected. The vulnerability was added to CISA KEV on 2026-08-31 and is being exploited in the wild as part of an AI-orchestrated campaign that compromised roughly 395–440 organizations.
    · PaperCut MF · PaperCut NG KEVlarge
  • Privilege Escalation in Microsoft Active Directory Domain Services
    CVE-2021-42287 is an elevation-of-privilege vulnerability in Microsoft Active Directory Domain Services (AD DS) affecting multiple supported Windows Server releases. An attacker with any low-privileged domain account can trigger it — commonly in combination with the related sAMAccountName spoofing flaw CVE-2021-42278 — by manipulating account name attributes so the Kerberos Key Distribution Center issues tickets that grant rights normally reserved for domain controllers. The result is escalation from a standard user to domain administrator, giving the attacker full control over the Windows domain, a capability that is directly useful for ransomware deployment and data theft. Any organization running Active Directory on the affected Windows Server versions is exposed, which amounts to essentially every enterprise Windows network. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-11 with known ransomware use, and EPSS assigns it a 77.2% probability of exploitation within 30 days.
    · microsoft windows server 2004 windows server 2004 · microsoft windows server 2008 windows server 2008 KEV ransomwaremass
  • Privilege Escalation via sAMAccountName Spoofing in Microsoft Active Directory
    CVE-2021-42278 is an elevation of privilege flaw in Microsoft Active Directory Domain Services (AD DS) caused by improper handling of changes to a computer account's sAMAccountName, allowing an attacker to 'spoof' a domain controller's name. A low-privileged authenticated user who can create or rename computer accounts (possible by default for ordinary domain users under MachineAccountQuota) renames a machine account to match a domain controller, obtains a Kerberos ticket for that name, and — typically chained with the related flaw CVE-2021-42287 — impersonates the domain controller to gain domain administrator rights. Successful exploitation yields full control of the Active Directory domain, which attackers, including ransomware operators, use to move laterally and deploy ransomware. Any organization running Active Directory on the affected Windows Server releases is exposed, though only servers with the AD DS role (domain controllers) reachable by an attacker with valid domain credentials are directly exploitable. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-11 with known ransomware use, and EPSS assigns a 73.3% probability of exploitation within 30 days.
    · microsoft Windows Server 2004 (AD DS) Affected AD DS builds per Microsoft advisory; source data lists no specific version ranges · microsoft Windows Server 2008 (AD DS) Affected AD DS builds per Microsoft advisory; source data lists no specific version ranges KEV ransomwaremass
  • Command Injection in Ubiquiti UniFi Protect Application
    CVE-2026-77537 is an Improper Input Validation flaw (CWE-20) in Ubiquiti's UniFi Protect Application that allows a command injection against the host device. It is triggered by attacker-controlled input submitted over the network to the Protect application, and the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C) indicates no authentication, user interaction, or special conditions are required. A successful exploit yields code execution on the console hosting Protect, with critical confidentiality, integrity, and availability impact across the scope-changed host environment. Any organization or user running UniFi Protect — typically on a UniFi OS console that hosts the surveillance application — is potentially affected. There is no evidence of exploitation in the wild and no known public proof-of-concept; EPSS assigns a 0.9% probability of exploitation within 30 days, and vendor advisories report that fixes have shipped across the UniFi line.
    · Ubiquiti UniFi Protect Applicationlarge
  • Unauthenticated Command Injection in Ubiquiti UniFi Talk Application
    Ubiquiti's UniFi Talk Application contains an improper input validation flaw (CWE-20) that can be leveraged for command injection on the host device. The bug is triggered when untrusted input reaches the application over the network; per the CVSS vector, an attacker needs network reachability but no credentials, privileges, or user interaction (AV:N/AC:L/PR:N/UI:N). Successful exploitation yields command execution on the underlying Talk host with high impact to confidentiality, integrity, and availability and a scope change, earning the maximum CVSS 3.1 score of 10.0. Any organization running the UniFi Talk Application is affected; this is one of three 10.0-rated flaws patched across Ubiquiti's UniFi line, although the available data does not list specific affected or fixed versions. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently estimates a 1% probability of exploitation within 30 days.
    · Ubiquiti UniFi Talk Applicationmoderate
  • Authentication Bypass via CRLF Injection in Ubiquiti UniFi OS
    CVE-2026-77550 is an Improper Neutralization of CRLF (carriage return/line feed) sequences (CWE-93) in certain devices running Ubiquiti's UniFi OS, rated CVSS 10.0 with network reachability, no privileges, and no user interaction required. An attacker who can reach the vulnerable UniFi OS device or instance over the network sends crafted input containing CR/LF sequences, which disrupts authentication processing and lets the attacker bypass login entirely. Successful exploitation yields complete administrative control of the console or instance, with high impact on confidentiality, integrity, and availability, and the scope change in the CVSS vector indicates impact can extend beyond the vulnerable component to protected resources behind it. Any organization running an affected UniFi OS device is exposed, with the greatest risk for consoles or instances reachable from untrusted networks. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS puts near-term exploitation probability at about 0.5% (40th percentile); it is one of three 10.0-severity UniFi issues reported as fixed in recent updates.
    · Ubiquiti UniFi OS (certain devices/instances)mass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.