TL;DR
Ubiquiti published Security Advisory Bulletin 067 on August 26, 2026. It patches 22 vulnerabilities across the UniFi product line. Three reach the maximum CVSS 10.0, and many enable command injection. Update affected applications and devices now.
- Total: 22 CVEs
- Severity: 21 Critical · 1 High
- Actively exploited: None confirmed
- Highest severity: 10.0 (Critical · CVSSv3) — CVE-2026-77537
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Fixed in | Status |
|---|---|---|---|
| CVE-2026-77537 | 10 | 7.2.105 | Not exploited |
| CVE-2026-77550 | 10 | 5.1.37, 5.1.31, 5.1.32 (+1) | Not exploited |
| CVE-2026-77554 | 10 | 5.3.2 | Not exploited |
| CVE-2026-77533 | 9.9 | 7.2.105 | Not exploited |
| CVE-2026-77534 | 9.9 | 5.1.37, 5.1.31, 5.1.32 | Not exploited |
| CVE-2026-77536 | 9.9 | 5.1.37, 5.1.31, 5.1.32 | Not exploited |
| CVE-2026-77543 | 9.9 | 4.3.5 | Not exploited |
| CVE-2026-77546 | 9.9 | 4.3.5 | Not exploited |
Why These UniFi Vulnerabilities Matter
UniFi gear runs networks, cameras, and access control for many businesses. A break in these systems exposes both data and physical security. This UniFi vulnerability batch is unusually large and severe.
Most flaws rate Critical. Because several allow command injection over the network, attackers could seize host devices. As a result, exposed UniFi consoles face real risk.
How the Attacks Work
Command Injection Flaws
Many bugs stem from improper input validation. In practice, that lets an attacker run commands on the host device. The advisory describes several as an attacker who could execute a Command Injection on the host device.
Three flaws reach a perfect 10.0 score. CVE-2026-77537 hits the UniFi Protect Application and needs no privileges. CVE-2026-77554 affects UniFi Talk with the same command injection impact. CVE-2026-77550 allows an authentication bypass on UniFi OS devices.
Privilege Escalation and Auth Bypass
Other flaws involve improper access control. These let a low-privilege user climb higher on UniFi OS or applications. Two CRLF injection bugs can bypass authentication on UniFi OS entirely.
Is It Being Exploited?
No exploitation in the wild has been confirmed. Ubiquiti reports no active attacks. Likewise, no public proof-of-concept exists yet.
Affected Versions
The flaws span many products. Key examples include UniFi Protect Application 7.1.87 and earlier, UniFi Network Application 10.4.57 and earlier, and UniFi OS Server 5.1.21 and earlier. UniFi Access, Talk, Connect, and several hardware consoles are also affected.
Patch and Mitigation Steps
Update each affected product to its fixed release. For example, move UniFi Protect to 7.2.105, Network Application to 10.5.67, and UniFi OS Server to 5.1.37. The full list appears in Ubiquiti’s Security Advisory Bulletin 067. Apply every relevant update without delay.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!