logo

Ubiquiti patches three max severity security vulnerabilities

ID: e7c319d8-efda-5d32-acbd-d6940d057c5d

STIX ID: report--e7c319d8-efda-5d32-acbd-d6940d057c5d

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Sergiu Gatlan

...
...

Ubiquiti released patches for three maximum-severity, unauthenticated remote vulnerabilities impacting UniFi Protect, UniFi Talk, and UniFi OS—rooted in improper input validation, CRLF injection, and command injection—and urged updating to fixed versions; the report highlights a large number of Internet-exposed UniFi instances and contextualizes the risk with past Ubiquiti-focused botnets and exploited vulnerabilities, though it notes no confirmed in-the-wild exploitation of these specific CVEs yet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.