HomeSecurityUbiquiti: Critical vulnerability in UniFi OS - Update now

Ubiquiti: Critical vulnerability in UniFi OS – Update now

Ubiquiti has released a significant set of security updates for its UniFi OS , fixing a total of seven critical vulnerabilities that could allow attackers to gain control of vulnerable devices. Among them is the vulnerability CVE-2026-50746 , which has been rated as maximum severity and is related to command injection attacks , one of the most dangerous categories of flaws in cybersecurity.

Ubiquiti critical vulnerability in UniFi OS

The fixes concern not only the UniFi OS operating environment, but also several of the company's most popular applications and devices, which makes their immediate installation particularly important for businesses and organizations that rely on the Ubiquiti ecosystem.

The CVE-2026-50746 vulnerability and potential risks

The most serious of the new security issues was found in the UniFi Connect, versions 3.4.16 and earlier. This is the platform used to centrally manage smart installations, such as LED lighting systems, electric vehicle chargers, and other automated functions in commercial buildings.

According to Ubiquiti, an attacker with access to the same network could exploit inadequate access control mechanisms to perform command injection on the target device. Such a scenario could lead to command execution, compromise of the device, and potential expansion of the attack across the entire corporate network.

See also: CISA KEV: 4 Adobe, Joomla and Langflow vulnerabilities

For this reason, the company calls on all administrators to immediately upgrade UniFi Connect to version 3.4.20 or later, where this specific security vulnerability has now been addressed.

Ubiquiti: Critical vulnerability in UniFi OS - Update now

Six more critical fixes

In addition to CVE-2026-50746, Ubiquiti patched six other high-critical vulnerabilities, which affect applications such as UniFi Talk, UniFi Access , and UniFi Protect, as well as the UniFi OS server itself.

The fixes also affect a large number of the company's products, including routers, gateways, NAS systems and surveillance solutions.

Notably, six of the seven flaws can be exploited through low-sophistication attacks and without requiring any action from the end user. This means that an attacker can, under certain conditions, exploit the vulnerabilities without having to trick the victim or convince them to execute a file.

So far, Ubiquiti says there is no confirmed information that these vulnerabilities were used in actual cyberattacks before the patches were released.

More than 100,000 installations exposed online

Of particular concern is data from threat intelligence firm Censys, which says that more than 100,000 UniFi OS installations are visible over the internet.

Nearly half of them are in the United States, and it is not yet known how many have already been updated or how many are honeypots. Furthermore, Censys' scans are based on historical data and may not fully reflect the current situation.

See also: GhostLock: 15-year-old Linux vulnerability for root access

However, this number demonstrates how large the attack surface is that can be exploited by cybercriminals in the event of a delay in updates.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Ubiquiti: Critical vulnerability in UniFi OS - Update now

Ubiquiti remains a constant target of attacks

Ubiquiti's products have been targeted by both organized cybercrime groups and state-sponsored attackers for years.

A notable example was the Moobot, which was dismantled by the FBI in early 2024. This network consisted of compromised Ubiquiti EdgeOS and, according to US authorities, was used by the Russian intelligence agency GRU to route malicious internet traffic and conduct cyberespionage operations.

Similar warnings have been issued repeatedly by CISA, which has added several Ubiquiti vulnerabilities to the list of actively exploited security holes, requiring US federal agencies to implement fixes within strict time frames.

Why updates are critical

The Ubiquiti case is yet another reminder that network devices and management platforms are now prime targets for attackers. Unlike a personal computer, a compromised router or management server can act as an entry point into an entire corporate network, allowing data theft, malware installation, or even botnet creation.

See also: GitHub Agentic Workflows: Critical prompt injection vulnerability

Experts recommend that system administrators immediately install new versions of UniFi OS and related applications, limit where device exposure to the internet possible, and constantly monitor Ubiquiti’s official announcements for any new security updates. In a period where attacks on network infrastructure are constantly increasing, timely application of patches remains the most effective line of defense against modern cyber threats.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS