Ubiquiti security advisory (AV26-954)
Canada's Cyber Centre warns of vulnerabilities in multiple Ubiquiti UniFi gateways, routers, and firewalls and urges updates.
Canadian Centre for Cyber Security advisory AV26-954, dated September 23, 2026, says Ubiquiti products were affected by vulnerabilities as of September 22, 2026. Impacted products include Cloud Gateways, Dream Machines, Dream Routers, Dream Wall, and Enterprise Firewalls before 5.1.31, Express before 4.0.21, Express 7 before 5.1.31, and UniFi Gateways before 5.1.26. The bulletin names no CVEs, does not report exploitation, and urges administrators to review Ubiquiti's advisory and apply updates.
- AV26-954 covers several Ubiquiti UniFi gateway and firewall lines.
- Most listed products need 5.1.31 or later; Express needs 4.0.21.
- UniFi Gateways are affected before version 5.1.26.
- The bulletin names no CVEs and does not report exploitation.
Full article87 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-954
Date: September 23, 2026
As of September 22, 2026, Ubiquiti Inc is affected by vulnerabilities in the following products:
- Cloud Gateways
- Prior to 5.1.31
- Dream Machines
- Prior to 5.1.31
- Dream Routers
- Prior to 5.1.31
- Dream Wall
- Prior to 5.1.31
- Enterprise Firewalls
- Prior to 5.1.31
- Express
- Prior to 4.0.21
- Express 7
- Prior to 5.1.31
- UniFi Gateways
- Prior to 5.1.26
The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/ubiquiti-security-advisory-av26-954