logo

Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS

ID: 18ee299e-95ef-535e-8431-6c8a64873357

STIX ID: report--18ee299e-95ef-535e-8431-6c8a64873357

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-07-08

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

Ubiquiti released updates to address multiple critical vulnerabilities across UniFi Connect, Talk, Access, Protect, and UniFi OS (including CVE-2026-50746, CVE-2026-50747, CVE-2026-50748, CVE-2026-54400, CVE-2026-55115, CVE-2026-54402, and CVE-2026-55116) that could enable command injection, SSRF, privilege escalation, and unauthorized changes; affected versions and fixed release numbers are listed. There is no evidence these specific flaws have been exploited in the wild, but related UniFi OS vulnerabilities were recently flagged by CISA as weaponized and prior campaigns (e.g., MooBot) have enlisted compromised Ubiquiti devices into botnets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.