logo

Critical Ubiquiti UniFi Vulnerabilities Allow Attackers to Seize Full Control of Underlying Systems

ID: 80e55912-6c43-52a9-a588-5ed8d94bb554

STIX ID: report--80e55912-6c43-52a9-a588-5ed8d94bb554

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-03-19

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Ubiquiti UniFi Vulnerabilities:** Ubiquiti disclosed two critical-to-high vulnerabilities in the UniFi Network Application — CVE-2026-22557 (CVSS 10.0), an unauthenticated path traversal that can allow full administrative compromise of hosts, and CVE-2026-22558 (CVSS 7.7), an authenticated NoSQL injection enabling privilege escalation — with affected versions listed and patched releases/mitigations advised; administrators are urged to update immediately and limit network exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.