logo

Three 10.0 security flaws fixed across Ubiquiti’s UniFi line

ID: dfe7002f-1b5a-5210-866d-fa7b9d73f9b9

STIX ID: report--dfe7002f-1b5a-5210-866d-fa7b9d73f9b9

Feed Name: CyberScoop

Threat Score
70/100

Date Published: 2026-08-26

Date Updated: 2026-08-27

Author: Tim Starks

...
...

Ubiquiti patched 22 vulnerabilities affecting primarily its UniFi product line, including three maximum-severity (CVSS 10.0) improper-access-control flaws—CVE-2026-77537, CVE-2026-77550, CVE-2026-77554—that could allow attackers to gain device or application privileges; other disclosed issues enable authentication bypass or arbitrary command execution. The company published mitigation guidance but did not report confirmed in-the-wild exploitation of these specific flaws, although CISA has previously listed three Ubiquiti vulnerabilities as known to be exploited.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.