Ubiquiti has released a significant set of security updates for its UniFi OS , fixing a total of seven critical vulnerabilities that could allow attackers to gain control of vulnerable devices. Among them is the vulnerability CVE-2026-50746 , which has been rated as maximum severity and is related to command injection attacks , one of the most dangerous categories of flaws in cybersecurity.

The fixes concern not only the UniFi OS operating environment, but also several of the company's most popular applications and devices, which makes their immediate installation particularly important for businesses and organizations that rely on the Ubiquiti ecosystem.
The CVE-2026-50746 vulnerability and potential risks
The most serious of the new security issues was found in the UniFi Connect, versions 3.4.16 and earlier. This is the platform used to centrally manage smart installations, such as LED lighting systems, electric vehicle chargers, and other automated functions in commercial buildings.
According to Ubiquiti, an attacker with access to the same network could exploit inadequate access control mechanisms to perform command injection on the target device. Such a scenario could lead to command execution, compromise of the device, and potential expansion of the attack across the entire corporate network.
See also: CISA KEV: 4 Adobe, Joomla and Langflow vulnerabilities
For this reason, the company calls on all administrators to immediately upgrade UniFi Connect to version 3.4.20 or later, where this specific security vulnerability has now been addressed.

Six more critical fixes
In addition to CVE-2026-50746, Ubiquiti patched six other high-critical vulnerabilities, which affect applications such as UniFi Talk, UniFi Access , and UniFi Protect, as well as the UniFi OS server itself.
The fixes also affect a large number of the company's products, including routers, gateways, NAS systems and surveillance solutions.
Notably, six of the seven flaws can be exploited through low-sophistication attacks and without requiring any action from the end user. This means that an attacker can, under certain conditions, exploit the vulnerabilities without having to trick the victim or convince them to execute a file.
So far, Ubiquiti says there is no confirmed information that these vulnerabilities were used in actual cyberattacks before the patches were released.
More than 100,000 installations exposed online
Of particular concern is data from threat intelligence firm Censys, which says that more than 100,000 UniFi OS installations are visible over the internet.
Nearly half of them are in the United States, and it is not yet known how many have already been updated or how many are honeypots. Furthermore, Censys' scans are based on historical data and may not fully reflect the current situation.
See also: GhostLock: 15-year-old Linux vulnerability for root access
However, this number demonstrates how large the attack surface is that can be exploited by cybercriminals in the event of a delay in updates.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Ubiquiti remains a constant target of attacks
Ubiquiti's products have been targeted by both organized cybercrime groups and state-sponsored attackers for years.
A notable example was the Moobot, which was dismantled by the FBI in early 2024. This network consisted of compromised Ubiquiti EdgeOS and, according to US authorities, was used by the Russian intelligence agency GRU to route malicious internet traffic and conduct cyberespionage operations.
Similar warnings have been issued repeatedly by CISA, which has added several Ubiquiti vulnerabilities to the list of actively exploited security holes, requiring US federal agencies to implement fixes within strict time frames.
Why updates are critical
The Ubiquiti case is yet another reminder that network devices and management platforms are now prime targets for attackers. Unlike a personal computer, a compromised router or management server can act as an entry point into an entire corporate network, allowing data theft, malware installation, or even botnet creation.
See also: GitHub Agentic Workflows: Critical prompt injection vulnerability
Experts recommend that system administrators immediately install new versions of UniFi OS and related applications, limit where device exposure to the internet possible, and constantly monitor Ubiquiti’s official announcements for any new security updates. In a period where attacks on network infrastructure are constantly increasing, timely application of patches remains the most effective line of defense against modern cyber threats.
Source: www.bleepingcomputer.com
