60
60
60
60
60
60
60
60
60
60
60
60
60
57
60
CVE-2026-34908: Ubiquiti Networks UniFi OS Server access control ...
CVE-2026-34908, a CVSS 10.0 access-control bypass in Ubiquiti UniFi OS, was added to CISA's KEV catalog amid reported active exploitation.
CISA added CVE-2026-34908 to the Known Exploited Vulnerabilities catalog on June 23, 2026, with remediation due June 26 under BOD 26-04 guidance. The CVSS 10.0 improper access control flaw (CWE-284) in Ubiquiti UniFi OS allows unauthorized system changes without authentication. Multiple news reports referenced by the page describe the max-severity UniFi flaws being exploited in attacks, and an official patch is available.
68
50
57
60
60
45
60
60
60
Week in review: Firmware-level Android backdoor found on tablets, Dell zero-day exploited since 2024
60
60
60
60
60
57
60
60
60
60
60
60
60
60
60
60