top of page
perceptive_background_267k.jpg

Ubiquiti patches three max severity security vulnerabilities

Published:

26 augustus 2026 om 15:17:54

Alert date:

26 augustus 2026 om 16:00:50

Source:

bleepingcomputer.com

Click to open the original link from this advisory

Network Infrastructure, Mobile & IoT, Zero-Day Vulnerabilities, Identity & Access

Ubiquiti has released security patches addressing three maximum-severity vulnerabilities in its products. These vulnerabilities can be exploited remotely by threat actors without requiring any privileges, making them especially dangerous. The flaws represent critical risks to organizations and individuals using Ubiquiti networking equipment. Ubiquiti has urged users to apply the patches immediately to mitigate potential exploitation. No additional technical details about specific CVEs or exploitation in the wild were provided in the article excerpt.

Technical details

Ubiquiti disclosed and patched three maximum-severity (CVSS 10) vulnerabilities. CVE-2026-77537 is an improper input validation flaw in the UniFi Protect Application video surveillance management platform, exploitable by unauthenticated remote attackers. CVE-2026-77550 is a CRLF injection vulnerability in UniFi OS devices/instances that allows remote, unprivileged attackers to bypass authentication by exploiting improper neutralization of CRLF sequences. CVE-2026-77554 is a command injection flaw stemming from improper input validation in the UniFi Talk Application VoIP phone system. All three vulnerabilities can be exploited remotely without authentication, require low attack complexity, and do not require user interaction. Additionally, Ubiquiti patched 18 critical-severity issues on the same day affecting UniFi OS Server, UniFi Network Application, UniFi Protect AI Key, and various routers, gateways, NAS, and surveillance systems. Over 100,000 UniFi OS instances are exposed on the internet according to Censys. Previously, similar UniFi OS vulnerabilities were chained to achieve remote code execution with elevated privileges. The Moobot botnet, used by Russian GRU, previously leveraged Ubiquiti devices for cyberespionage operations.

Mitigation steps:

Immediately update UniFi Protect Application to version 7.2.105 or later. Update UniFi Talk Application to version 5.3.2 or later. Update UniFi OS Server beyond version 5.1.21. Apply all patches released in Security Advisory Bulletin-067 addressing 18 additional critical vulnerabilities. Audit internet-exposed UniFi OS instances and restrict public access where possible. Monitor for unauthorized access attempts or authentication bypass activity on UniFi OS devices. Review network segmentation to limit attacker lateral movement in case of compromise. Check CISA advisories for mandated patching deadlines if operating in a federal agency context.

Affected products:

UniFi Protect Application (versions prior to 7.2.105)
UniFi Talk Application (versions prior to 5.3.2)
UniFi OS Server (version 5.1.21 and earlier)
UniFi Network Application
UniFi Protect AI Key
Ubiquiti routers
Ubiquiti gateways
Ubiquiti NAS
Ubiquiti surveillance systems
Ubiquiti Edge OS routers

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page