Active Exploitation of Critical Vulnerabilities in Lantronix and Ubiquiti Devices
ID: 2add96ba-f37b-5383-a8ee-6dafc1b4d1e7
STIX ID: report--2add96ba-f37b-5383-a8ee-6dafc1b4d1e7
Feed Name: ThreatCluster
Threat Score
CISA confirmed active exploitation of critical vulnerabilities affecting Lantronix EDS5000-series (CVE-2025-67038 — unauthenticated command injection) and Ubiquiti UniFi OS (CVE-2026-34908/34909/34910 — remote code execution). Both were added to CISA's Known Exploited Vulnerabilities catalog on June 23, 2026, and federal agencies were ordered to apply patches by June 26, 2026 due to the significant risk these flaws pose to network and industrial infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
