logo

Ubiquiti defect poses account takeover risk for UniFi Networking Application users

ID: 7d7d2991-a9b7-5d30-9c6f-7bb98f496805

STIX ID: report--7d7d2991-a9b7-5d30-9c6f-7bb98f496805

Feed Name: CyberScoop

Threat Score
80/100

Date Published: 2026-03-20

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

Ubiquiti disclosed and patched a critical CVSS 10 path-traversal vulnerability (CVE-2026-22557) in the UniFi Network Application that can enable unauthenticated remote account takeover, alongside a privilege-escalation bug (CVE-2026-22558). Censys observed roughly 88,000 UniFi Network Application hosts exposed to the internet, many in the U.S.; although no public proof-of-concept or confirmed exploitation had been observed, the low exploitation complexity and high exposure make rapid patching imperative.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.