Ubiquiti has patched two critical security vulnerabilities in its UniFi Network app , one of which is rated as critical, as it could allow attackers to gain complete control over user accounts . The disclosure brings back to the forefront the security issues surrounding popular network management platforms, particularly in enterprise and organizational environments.

What is the UniFi Network and why it is a critical target
The UniFi Network app, also known as the UniFi Controller, is the core management tool for Ubiquiti's ecosystem of devices, including access points, switches, and gateways. It is a tool that allows administrators to configure, monitor, and optimize network performance from a single interface.
See also: CISA: New Zimbra and SharePoint vulnerabilities in the KEV Catalog
With features like real-time traffic dashboards, visual topology maps, and optimization tips, the platform is widely used by both small businesses and large organizations. Its widespread adoption makes it a particularly attractive target for cyberattacks.
The vulnerability CVE-2026-22557 and the risk of account takeover
The more serious of the two vulnerabilities, listed as CVE-2026-22557, affects versions of the application up to 10.1.85 and has been fixed in 10.1.89 and later. The vulnerability relies on a Path Traversal, allowing unauthorized users to gain access to files on the underlying system.
The worrying thing is that the exploit can be carried out easily and without any interaction on the user's part. This means that an attacker with simple network access can move laterally, collect sensitive data and ultimately take over accounts.
Second vulnerability and privilege escalation
At the same time, Ubiquiti has also fixed a second security issue related to Authenticated NoSQL Injection. In this case, a user with already limited access to the system could exploit the gap to gain higher privileges.
See also: Fortinet: Critical SQL Injection vulnerability in FortiClient EMS

The combined exploitation of the two vulnerabilities creates an especially dangerous scenario, where an attacker could initially gain access to critical files and then elevate his privileges, gaining full control of the network.
The importance of proper development and updates
Ubiquiti itself recommends as a best practice to deploy the application via UniFi Cloud gateways, rather than self-hosted environments such as local servers or laptops. However, regardless of the deployment model, timely installation of security updates remains crucial.
Organizations that delay upgrading their systems are exposed to increased risk, particularly when it comes to vulnerabilities that can be exploited without much technical sophistication.
History of attacks and use in botnets
Ubiquiti products are no stranger to cybercriminals. In recent years, they have been targeted by both independent hacking groups and state-sponsored threat actors. These devices have been repeatedly used to create botnets, which are used to hide malicious activity and carry out large-scale attacks.
A notable example is an FBI operation in 2024 that dismantled a botnet based on compromised Ubiquiti EdgeOS routers. This network was allegedly used by the Russian intelligence agency GRU to funnel malicious traffic into attacks against the United States and its allies.
See also: RegPwn: New critical vulnerability in Windows
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The broader impacts for network security
Recent vulnerabilities in the UniFi Network highlight the importance of security at the network infrastructure level. As more and more businesses rely on centralized management systems, a breach of such a tool can have ripple effects.
The need to adopt practices such as zero trust, network segmentation, and continuous monitoring is more urgent than ever. At the same time, administrators are being asked to review access levels and restrict permissions where possible.
The Ubiquiti case is yet another reminder that even the most widespread and reliable tools are not invulnerable, and that cybersecurity requires continuous vigilance and immediate response to new threats.
Source: www.bleepingcomputer.com
