ZeroHour
CyberScooppublished ()ingested @timstarks

Three 10.0 security flaws fixed across Ubiquiti’s UniFi line

AI summary · glm-5.3-flash

Ubiquiti patches 22 UniFi vulnerabilities, 21 rated critical including three CVSS 10.0 flaws enabling unauthorized access.

Ubiquiti disclosed and patched 22 vulnerabilities, 21 rated critical and three assigned the maximum CVSS 10.0 score: CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554. All three involve improper access control that could let attackers gain privileges, while other flaws permit authentication bypass or arbitrary command execution. All but one of the 22 affect the UniFi product line. The company did not confirm whether any were exploited before patching.

  • Three CVSS 10.0 flaws: CVE-2026-77537, -77550, -77554
  • 21 of 22 flaws rated critical; one rated high
  • Improper access control affects at least 8 vulnerabilities
  • CISA added three Ubiquiti flaws to KEV earlier this year
VendorsUbiquiti
ProductsUniFi
OrganizationsCISACyberScoop

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-77554
+1 in the same advisory: …77537
Unauthenticated Command Injection in Ubiquiti UniFi Talk Application

Ubiquiti's UniFi Talk Application contains an improper input validation flaw (CWE-20) that can be leveraged for command injection on the host device. The bug is triggered when untrusted input reaches the application over the network; per the CVSS vector, an attacker needs network reachability but no credentials, privileges, or user interaction (AV:N/AC:L/PR:N/UI:N). Successful exploitation yields command execution on the underlying Talk host with high impact to confidentiality, integrity, and availability and a scope change, earning the maximum CVSS 3.1 score of 10.0. Any organization running the UniFi Talk Application is affected; this is one of three 10.0-rated flaws patched across Ubiquiti's UniFi line, although the available data does not list specific affected or fixed versions. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently estimates a 1% probability of exploitation within 30 days.

Do: Update the UniFi Talk Application to the latest patched release published by Ubiquiti; the source data does not name the fixed version, so consult Ubiquiti's release notes for the patch released alongside the three 10.0-rated UniFi fixes. Restrict network access to the Talk Application to trusted management segments, since exploitation requires only network reachability with no authentication. Given the maximum-severity score and lack of public exploitation so far, prioritize patching internet-reachable deployments and monitor for emerging PoCs.

10.0<1%
  • Ubiquiti UniFi Talk Application
moderatelikely low tens of thousands of deployments worldwide at most (no published install counts; niche product line)
CVE-2026-77550
Authentication Bypass via CRLF Injection in Ubiquiti UniFi OS

CVE-2026-77550 is an Improper Neutralization of CRLF (carriage return/line feed) sequences (CWE-93) in certain devices running Ubiquiti's UniFi OS, rated CVSS 10.0 with network reachability, no privileges, and no user interaction required. An attacker who can reach the vulnerable UniFi OS device or instance over the network sends crafted input containing CR/LF sequences, which disrupts authentication processing and lets the attacker bypass login entirely. Successful exploitation yields complete administrative control of the console or instance, with high impact on confidentiality, integrity, and availability, and the scope change in the CVSS vector indicates impact can extend beyond the vulnerable component to protected resources behind it. Any organization running an affected UniFi OS device is exposed, with the greatest risk for consoles or instances reachable from untrusted networks. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS puts near-term exploitation probability at about 0.5% (40th percentile); it is one of three 10.0-severity UniFi issues reported as fixed in recent updates.

Do: Apply the latest UniFi OS firmware/update release from Ubiquiti, which includes the fixes for this and the other two 10.0 flaws in the same advisory batch. Until patched, restrict network access to UniFi OS management interfaces (e.g., firewall rules or VPN-only access) and avoid exposing consoles directly to the internet. Check internet-facing UniFi OS instances for exposure and monitor for vendor advisories identifying specific affected/fixed versions.

10.0<1%
  • Ubiquiti UniFi OS (certain devices/instances)
massmillions of installed UniFi devices, with on the order of 100,000+ consoles/instances likely internet-exposed
Full article510 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The communications product company disclosed 22 total Wednesday, all but one of which was rated “critical” at 9.0 or higher.

Listen to this article

0:00

Learn more.

The UniFi brand logo on March 5, 2026. (Photo by Joan Cros/NurPhoto via Getty Images)

Ubiquiti has patched 21 critical vulnerabilities, three of which were rated the highest severity possible, the communications product company said Wednesday in a security bulletin.

In all, the company patched 22 vulnerabilities, with the last one rated “high,” it said in the bulletin.

Three of the vulnerabilities had a Common Vulnerability Scoring System rating of 10 out of 10. Each of them would allow a hacker to access privileges on the device or application.

All but one of the 22 vulnerabilities affect the UniFi line of products. The three maximum-security vulnerabilities are CVE-2026-77537, CVE-2026-77550 and CVE-2026-77554.

In all three, hackers could exploit an improper access control vulnerability, the same kind in seven of the total vulnerabilities Ubiquiti disclosed Wednesday. Other vulnerabilities would allow hackers to do things like bypass authentication or run arbitrary commands.

Ubiquiti, which claimed revenues of $2.57 billion last year, released the bulletin without commentary, besides identifying the vulnerabilities and recommended mitigations. The company did not immediately respond to a request for comment about whether it had seen any of the exploits used in the wild before they were patched.

The trio of maximum-security vulnerabilities patched equals the total the company had disclosed this year before Wednesday.

In March, the company disclosed that it had patched a single maximum-security vulnerability. It disclosed one more in both May and July of this year.

Two months ago, the Cybersecurity and Infrastructure Security Agency added three Ubiquiti vulnerabilities to its list of flaws that were known to have been exploited, sometimes called the agency’s “must-patch” list.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ubiquiti-unifi-critical-vulnerabilities-patched/