T

Threats

Ubiquiti Patches Three Critical UniFi Vulnerabilities

Ubiquiti has released security updates for three critical vulnerabilities across its UniFi ecosystem. All three flaws have a CVSS v3.1 score of 10.0 and can be exploited over a network with low attack complexity, without privileges or user interaction.

The vulnerabilities affect UniFi Protect Application, a broad range of UniFi OS devices and instances, and UniFi Talk Application. Successful exploitation could allow command execution on the host device or authentication bypass, creating a serious risk of device, service and data compromise.

There is no confirmed exploitation in the wild as of 26 August 2026. Organisations should not delay patching.


Overview

  • CVE: CVE-2026-77537, CVE-2026-77550, CVE-2026-77554

  • Severity: Critical

  • CVSS: 10.0 for each vulnerability

  • Publication date: 26 August 2026

  • Attack requirements: Network access, low complexity, no privileges, no user interaction


Affected Versions

UniFi Protect Application - CVE-2026-77537

UniFi OS Devices and Instances - CVE-2026-77550

  • Affected: UniFi OS Server versions earlier than 5.1.37

  • Fixed: UniFi OS Server version 5.1.37 and later

  • Not affected: UniFi OS Server version 5.1.37 and later

  • Source: Ubiquiti Security Advisory Bulletin 067

  • Affected: Cloud Keys, Network Video Recorders, Enterprise Network Video Recorders, Enterprise Network Attached Storage, Dream Machines, Enterprise Firewall Core, Dream Routers, Enterprise Fortress Gateway, Cloud Gateways, Dream Wall and Express 7 versions earlier than 5.1.31

  • Fixed: Version 5.1.31 and later for the listed product families

  • Not affected: Version 5.1.31 and later for the listed product families

  • Source: Ubiquiti Security Advisory Bulletin 067

  • Affected: Network Attached Storage versions earlier than 5.1.32

  • Fixed: Version 5.1.32 and later

  • Not affected: Version 5.1.32 and later

  • Source: Ubiquiti Security Advisory Bulletin 067

  • Affected: Express versions earlier than 4.0.17

  • Fixed: Version 4.0.17 and later

  • Not affected: Version 4.0.17 and later

  • Source: Ubiquiti Security Advisory Bulletin 067

UniFi Talk Application - CVE-2026-77554


Vulnerability Breakdown

CVE-2026-77537 - UniFi Protect Command Injection

  • Severity: Critical

  • CVSS: 10.0

  • Description: Improper input validation in UniFi Protect Application can allow a malicious actor to inject commands on the host device.

  • Impact: Successful exploitation could compromise the confidentiality, integrity and availability of the host device.

  • Conditions: The attacker requires network access. No privileges or user interaction are required.

CVE-2026-77550 - UniFi OS Authentication Bypass

  • Severity: Critical

  • CVSS: 10.0

  • Description: Improper neutralisation of CRLF sequences in affected UniFi OS devices and instances can allow an attacker to bypass authentication.

  • Impact: Successful exploitation could provide unauthorised access to affected management functions and expose the device or instance to further compromise.

  • Conditions: The attacker requires network access. No privileges or user interaction are required.

CVE-2026-77554 - UniFi Talk Command Injection

  • Severity: Critical

  • CVSS: 10.0

  • Description: Improper input validation in UniFi Talk Application can allow a malicious actor to inject commands on the host device.

  • Impact: Successful exploitation could compromise the confidentiality, integrity and availability of the host device and its communications services.

  • Conditions: The attacker requires network access. No privileges or user interaction are required.


Mitigation

  • Update UniFi Protect Application to version 7.2.105 or later.

  • Update UniFi Talk Application to version 5.3.2 or later.

  • Update each affected UniFi OS product to the fixed version listed above or a later release.

  • Confirm the update completed successfully and verify the installed version on each device or instance.


Summary for IT Teams

  • Products: Ubiquiti UniFi Protect Application, UniFi OS devices and instances, and UniFi Talk Application

  • Threat Level: Critical, CVSS 10.0

  • Action Required: Identify affected systems and apply the relevant Ubiquiti update immediately. Prioritise any management interface reachable from untrusted or broadly accessible network segments.


Reference


Need Help?

Secure ISS can help your organisation identify exposed UniFi systems, assess affected versions and prioritise remediation.

Please contact Secure ISS on 1300 769 460 for assistance.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.