Ubiquiti Addresses Three Critical Security Vulnerabilities with Urgent Fix

www.news4hackers.com-ubiquiti-addresses-three-critical-security-vulnerabilities-with-urgent-fix-ubiquiti-addresses-three-critical-security-vulnerabilities-with-urgent-fix

Ubiquiti has issued security updates to address three critical vulnerabilities that could be exploited remotely without requiring user authentication.

Critical Vulnerabilities Addressed

Ubiquiti has issued security updates to address three critical vulnerabilities that could be exploited remotely without requiring user authentication. The first flaw, designated CVE-2026-77537, involves a vulnerability in the UniFi Protect Application’s video surveillance management platform. This weakness arises from improper input validation, allowing unauthorized attackers to compromise unpatched devices. A second vulnerability, CVE-2026-77550, is a CRLF injection flaw affecting UniFi OS devices or instances. This flaw enables attackers to bypass authentication mechanisms when they have network access. The third issue, CVE-2026-77554, is a command injection vulnerability stemming from inadequate input validation in the UniFi Talk Application’s VoIP system.

Patches and Affected Versions

Patches for these issues are included in UniFi Protect Application version 7.2.105 or later, UniFi Talk Application 5.3.2 or later, and UniFi OS Server 5.1.21 and earlier. Ubiquiti has not confirmed if these vulnerabilities were exploited prior to their disclosure, but noted that they could be leveraged in low-complexity attacks without user interaction. On the same day, the company also resolved 18 additional critical-severity flaws impacting various products, including UniFi OS Server, UniFi Network Application, UniFi Protect AI Key hardware, and multiple routers, gateways, NAS devices, and surveillance systems.

Exposure and Past Attacks

Security researchers at Censys have identified over 100,000 UniFi OS instances exposed online, though the data may include historical scans or honeypots. Recent years have seen state-sponsored groups and cybercriminals target Ubiquiti products to create botnets for hiding malicious activities. For example, in February 2024, the FBI dismantled Moobot, a botnet composed of Ubiquiti Edge OS routers used by the GRU to anonymize cyberespionage operations. In June, CISA required federal agencies to secure systems against three previously patched UniFi OS vulnerabilities that were later exploited in active attacks.

Security firm Bishop Fox demonstrated that these flaws could be combined to achieve remote code execution with elevated privileges. Analysis of 338 million simulations across customer environments revealed that 63% of attacks succeed when valid credentials are present.

Blue Report 2026

The Blue Report 2026 evaluates defensive measures across 338 million simulations conducted in live production environments.

Additional Coverage

Additional coverage includes warnings about a new high-severity UniFi OS vulnerability, active exploitation of prior flaws, and other cybersecurity developments.


Blog Image

About Author

en_USEnglish