


Perceptive Security
SOC/SIEM Consultancy

Ubiquiti patches three max severity security vulnerabilities
Published:
26 augustus 2026 om 15:17:54
Alert date:
26 augustus 2026 om 16:00:50
Source:
bleepingcomputer.com
Network Infrastructure, Mobile & IoT, Zero-Day Vulnerabilities, Identity & Access
Ubiquiti has released security patches addressing three maximum-severity vulnerabilities in its products. These vulnerabilities can be exploited remotely by threat actors without requiring any privileges, making them especially dangerous. The flaws represent critical risks to organizations and individuals using Ubiquiti networking equipment. Ubiquiti has urged users to apply the patches immediately to mitigate potential exploitation. No additional technical details about specific CVEs or exploitation in the wild were provided in the article excerpt.
Technical details
Ubiquiti disclosed and patched three maximum-severity (CVSS 10) vulnerabilities. CVE-2026-77537 is an improper input validation flaw in the UniFi Protect Application video surveillance management platform, exploitable by unauthenticated remote attackers. CVE-2026-77550 is a CRLF injection vulnerability in UniFi OS devices/instances that allows remote, unprivileged attackers to bypass authentication by exploiting improper neutralization of CRLF sequences. CVE-2026-77554 is a command injection flaw stemming from improper input validation in the UniFi Talk Application VoIP phone system. All three vulnerabilities can be exploited remotely without authentication, require low attack complexity, and do not require user interaction. Additionally, Ubiquiti patched 18 critical-severity issues on the same day affecting UniFi OS Server, UniFi Network Application, UniFi Protect AI Key, and various routers, gateways, NAS, and surveillance systems. Over 100,000 UniFi OS instances are exposed on the internet according to Censys. Previously, similar UniFi OS vulnerabilities were chained to achieve remote code execution with elevated privileges. The Moobot botnet, used by Russian GRU, previously leveraged Ubiquiti devices for cyberespionage operations.
Mitigation steps:
Immediately update UniFi Protect Application to version 7.2.105 or later. Update UniFi Talk Application to version 5.3.2 or later. Update UniFi OS Server beyond version 5.1.21. Apply all patches released in Security Advisory Bulletin-067 addressing 18 additional critical vulnerabilities. Audit internet-exposed UniFi OS instances and restrict public access where possible. Monitor for unauthorized access attempts or authentication bypass activity on UniFi OS devices. Review network segmentation to limit attacker lateral movement in case of compromise. Check CISA advisories for mandated patching deadlines if operating in a federal agency context.
Affected products:
UniFi Protect Application (versions prior to 7.2.105)
UniFi Talk Application (versions prior to 5.3.2)
UniFi OS Server (version 5.1.21 and earlier)
UniFi Network Application
UniFi Protect AI Key
Ubiquiti routers
Ubiquiti gateways
Ubiquiti NAS
Ubiquiti surveillance systems
Ubiquiti Edge OS routers
Related links:
https://www.cve.org/CVERecord?id=CVE-2026-77537
https://cwe.mitre.org/data/definitions/20.html
https://cwe.mitre.org/data/definitions/93.html
http://www.cve.org/CVERecord?id=CVE-2026-77550
https://www.cve.org/CVERecord?id=%20CVE-2026-77554
https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9
https://platform.censys.io/search/report/data/table?q=%28host.services.endpoints.http.html_title%3A+%22UniFi+OS%22%29+and+not+labels%3A+%22HONEYPOT%22&field=host.location.country&num_buckets=500&filter_query=false&count_by=.
https://www.bleepingcomputer.com/news/security/fbi-disrupts-russian-moobot-botnet-infecting-ubiquiti-routers/
https://www.bleepingcomputer.com/news/security/russian-hackers-hijack-ubiquiti-routers-to-launch-stealthy-attacks/
https://www.bleepingcomputer.com/news/security/cisa-warns-of-max-severity-ubiquiti-flaws-exploited-in-attacks/
https://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-severity-unifi-os-vulnerabilities/
https://www.bleepingcomputer.com/news/security/critical-unifi-os-bug-lets-hackers-gain-root-without-authentication/
https://www.bleepingcomputer.com/news/security/ubiquiti-warns-of-new-max-severity-unifi-os-vulnerability/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
