logo

Ubiquiti warns of new max severity UniFi OS vulnerability

ID: 7346e63b-62d3-5ca5-bf66-7ade1e58a16f

STIX ID: report--7346e63b-62d3-5ca5-bf66-7ade1e58a16f

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-07-08

Date Updated: 2026-07-19

Author: Sergiu Gatlan

...
...

Ubiquiti released patches addressing seven critical UniFi OS vulnerabilities — including a maximum-severity command-injection (CVE-2026-50746) affecting UniFi Connect and six additional critical flaws across UniFi apps and devices. Censys reports over 100,000 internet-exposed UniFi OS instances, many in the U.S.; several flaws are low-complexity and chainable to achieve remote code execution. Given prior exploitation of Ubiquiti products by state-sponsored and criminal groups, the report urges immediate updates to mitigate widespread exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.