logo

Triple CVSS 10.0 Warning: Critical Ubiquiti UniFi OS Flaws Allow Unauthenticated Remote Takeovers

ID: 131d75ac-2be4-5400-bd4c-24f467deeee2

STIX ID: report--131d75ac-2be4-5400-bd4c-24f467deeee2

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Ddos

...
...

Ubiquiti published a security advisory disclosing five vulnerabilities in UniFi OS—three unauthenticated critical flaws (including improper access control, path traversal, and command injection) affecting UCG gateways, UDM series, UNVR recorders, UNAS storage appliances, and other models, plus two other high-severity flaws requiring authorization; administrators are urged to apply specified firmware updates (UniFi OS Server 5.0.8+, device updates 5.1.10–5.1.12+) immediately to mitigate remote network exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.