Ubiquiti is back in the cybersecurity spotlight after announcing fixes for three severity vulnerabilities high - affecting its core products and platforms. What's particularly concerning is that these vulnerabilities can be exploited remotely, without the attacker needing privileged access or user interaction.

Three critical vulnerabilities in different products
The first vulnerability, CVE-2026-77537, relates to insufficient input validation in the UniFi Protect Application video surveillance management platform. An unauthenticated attacker could exploit the issue on unpatched installations, gaining the ability to affect the operation of a system used to manage cameras and security infrastructure.
The second vulnerability, CVE-2026-77550, concerns CRLF injection. According to Ubiquiti, a malicious actor with network access could exploit the flaw to bypass authentication mechanisms on certain UniFi OS. Such a bypass is particularly serious, as authentication is a key barrier against unauthorized access.
See also: Gitea RCE: Critical vulnerability exploited by hackers
The third vulnerability, CVE-2026-77554 , is found in the UniFi Talk application , which supports VoIP phone services. It is a command injection issue that is also associated with insufficient input validation. If successfully exploited, such a bug could allow the execution of unauthorized commands in the affected environment.
Updates that need to be installed
The company has released fixes in the latest versions of these applications and platforms. UniFi Protect administrators should be using version 7.2.105 or later , while UniFi Talk requires version 5.3.2 or later . For UniFi OS Server , the relevant fix is linked to version 5.1.21 .
Patching should not be treated as a routine maintenance process. When a vulnerability can be exploited without much complexity and without user interaction, the window of opportunity an organization has to protect itself may be limited. Systems that are accessible from the internet require particular attention.

Over 100,000 installations online
The picture becomes even more alarming when you consider data from Censys, which identifies more than 100,000 UniFi OS installations exposed online. This number does not mean that all systems are vulnerable or that they are active targets. It may also include honeypots and results from previous scans, so it is not an accurate record of the current situation.
See also: NVIDIA NemoClaw: Vulnerability allows websites to manipulate AI agents
However, it does capture the size of the potential attack surface. For administrators, exposing a device to the internet significantly increases the need for immediate notification, limiting remote access , and constant monitoring for suspicious activity.
Ubiquiti is back in the spotlight
Ubiquiti products have been repeatedly targeted by both cybercriminal groups and state-affiliated organizations. A notable example was Moobot, a botnet based on Ubiquiti EdgeOS routers that, according to US authorities, was used by the Russian GRU to funnel malicious traffic and conceal cyberespionage activities.
This case illustrates why network devices should not be considered simply “infrastructure equipment.” A compromised router, gateway, or server can become an entry point, a staging area for attacks, or part of a larger botnet.
Previous vulnerabilities and chain attacks
The pressure on organizations has increased in recent months. CISA had asked federal agencies to immediately address three other critical vulnerabilities in UniFi OS, which had already begun to be exploited in real-world attacks. Later, researchers at Bishop Fox showed that some of these gaps could be combined into an exploit chain, ultimately leading to remote code execution with elevated privileges.
See also: Milesight IoT: Critical NFC vulnerability exposes LoRaWAN keys
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The new incident reminds us that the security of a network infrastructure does not depend solely on the existence of a firewall or a strong password. Regular firmware and software updates, disabling unnecessary services, limiting internet exposure, using multi-factor authentication where supported, and monitoring logs are critical lines of defense.
Ubiquiti has not yet clarified whether the three new vulnerabilities were exploited before the patches were released. However, the fact that they are classified as high-risk and exploitable, with relatively low complexity, makes installing the available updates immediately the safest option.
Source: www.bleepingcomputer.com
