Jump to content

Patch Now: Ubiquiti Drops Fixes for Three CVSS 10 Flaws Across UniFi Stack


If you manage any UniFi kit, it is time to schedule a maintenance window right away. Ubiquiti’s Security Advisory Bulletin 067 is a massive patch drop fixing 22 vulnerabilities across the stack, including three separate unauthenticated CVSS 10.0 flaws hitting UniFi Protect, UniFi OS, and UniFi Talk.

The Heavy Hitters

Having three simultaneous maximum-severity vulnerabilities in a single release is rare. None of them require existing credentials or user interaction, which makes them prime targets for anyone scanning your subnets.

The first big issue is CVE-2026-77537, a command injection bug in UniFi Protect that lets network attackers execute arbitrary commands directly on the host appliance. The second, CVE-2026-77550, is a CRLF injection flaw in UniFi OS that allows attackers to completely bypass authentication across Cloud Keys, Dream Machines, and UNVRs. The third, CVE-2026-77554, delivers another remote command injection vector inside the UniFi Talk VoIP suite.

The rest of the bulletin fixes 19 other issues ranging from CVSS 8.2 to 9.9. These cover privilege escalation, exposed debug endpoints, and secondary injection bugs across UniFi Network, Access, and Connect.

Component Issue Type Affected Fixed In
UniFi OS Server Auth bypass / Priv escalation \le 5.1.21 5.1.37+
UniFi OS Consoles (UDM, UNVR, Cloud Key) Auth bypass / Priv escalation \le 5.1.26 5.1.31 / 5.1.32+
UniFi OS Express Auth bypass \le 4.0.16 4.0.17+
UniFi Protect Remote command injection \le 7.1.87 7.2.105+
UniFi Talk Remote command injection \le 5.2.7 5.3.2+
UniFi Network Priv escalation / Command injection \le 10.4.57 10.5.67+
UniFi Access Priv escalation / Command injection \le 4.3.3 4.3.5+
UniFi Connect Priv escalation \le 3.24.20 3.24.22+
UID Enterprise Agent Command injection \le 1.61.8 1.62.1+
Protect AI Key Priv escalation \le 2.1.3 2.2.6+

 

More details: https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9

 


User Feedback

Recommended Comments

There are no comments to display.



Guest
Add a comment...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.




×
×
  • Create New...