logo

CISA warns of max severity Ubiquiti flaws exploited in attacks

ID: c611d2b7-8f31-54d7-b67f-143efa2ba998

STIX ID: report--c611d2b7-8f31-54d7-b67f-143efa2ba998

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-06-24

Date Updated: 2026-06-24

Author: Bill Toulas

...
...

CISA warns of active exploitation of several critical Ubiquiti UniFi OS vulnerabilities (CVE-2026-34908/34909/34910) enabling access control bypass, path traversal, and command injection leading to potential full system compromise; a separate critical Lantronix EDS5000 root-level command injection (CVE-2025-67038) is also highlighted. Vendors have released patches and detection scripts, and administrators are urged to apply updates or mitigations immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.