T
Threats
Ubiquiti Patches Three Critical UniFi Vulnerabilities
Ubiquiti has released security updates for three critical vulnerabilities across its UniFi ecosystem. All three flaws have a CVSS v3.1 score of 10.0 and can be exploited over a network with low attack complexity, without privileges or user interaction.
The vulnerabilities affect UniFi Protect Application, a broad range of UniFi OS devices and instances, and UniFi Talk Application. Successful exploitation could allow command execution on the host device or authentication bypass, creating a serious risk of device, service and data compromise.
There is no confirmed exploitation in the wild as of 26 August 2026. Organisations should not delay patching.
Overview
Severity: Critical
CVSS: 10.0 for each vulnerability
Publication date: 26 August 2026
Attack requirements: Network access, low complexity, no privileges, no user interaction
Affected Versions
UniFi Protect Application - CVE-2026-77537
Affected: Version 7.1.87 and earlier
Fixed: Version 7.2.105 and later
Not affected: Version 7.2.105 and later
UniFi OS Devices and Instances - CVE-2026-77550
Affected: UniFi OS Server versions earlier than 5.1.37
Fixed: UniFi OS Server version 5.1.37 and later
Not affected: UniFi OS Server version 5.1.37 and later
Affected: Cloud Keys, Network Video Recorders, Enterprise Network Video Recorders, Enterprise Network Attached Storage, Dream Machines, Enterprise Firewall Core, Dream Routers, Enterprise Fortress Gateway, Cloud Gateways, Dream Wall and Express 7 versions earlier than 5.1.31
Fixed: Version 5.1.31 and later for the listed product families
Not affected: Version 5.1.31 and later for the listed product families
Affected: Network Attached Storage versions earlier than 5.1.32
Fixed: Version 5.1.32 and later
Not affected: Version 5.1.32 and later
Affected: Express versions earlier than 4.0.17
Fixed: Version 4.0.17 and later
Not affected: Version 4.0.17 and later
UniFi Talk Application - CVE-2026-77554
Affected: Version 5.2.7 and earlier
Fixed: Version 5.3.2 and later
Not affected: Version 5.3.2 and later
Vulnerability Breakdown
CVE-2026-77537 - UniFi Protect Command Injection
Severity: Critical
CVSS: 10.0
Description: Improper input validation in UniFi Protect Application can allow a malicious actor to inject commands on the host device.
Impact: Successful exploitation could compromise the confidentiality, integrity and availability of the host device.
Conditions: The attacker requires network access. No privileges or user interaction are required.
CVE-2026-77550 - UniFi OS Authentication Bypass
Severity: Critical
CVSS: 10.0
Description: Improper neutralisation of CRLF sequences in affected UniFi OS devices and instances can allow an attacker to bypass authentication.
Impact: Successful exploitation could provide unauthorised access to affected management functions and expose the device or instance to further compromise.
Conditions: The attacker requires network access. No privileges or user interaction are required.
CVE-2026-77554 - UniFi Talk Command Injection
Severity: Critical
CVSS: 10.0
Description: Improper input validation in UniFi Talk Application can allow a malicious actor to inject commands on the host device.
Impact: Successful exploitation could compromise the confidentiality, integrity and availability of the host device and its communications services.
Conditions: The attacker requires network access. No privileges or user interaction are required.
Mitigation
Update UniFi Protect Application to version 7.2.105 or later.
Update UniFi Talk Application to version 5.3.2 or later.
Update each affected UniFi OS product to the fixed version listed above or a later release.
Confirm the update completed successfully and verify the installed version on each device or instance.
Summary for IT Teams
Products: Ubiquiti UniFi Protect Application, UniFi OS devices and instances, and UniFi Talk Application
Threat Level: Critical, CVSS 10.0
Action Required: Identify affected systems and apply the relevant Ubiquiti update immediately. Prioritise any management interface reachable from untrusted or broadly accessible network segments.
Reference
Need Help?
Secure ISS can help your organisation identify exposed UniFi systems, assess affected versions and prioritise remediation.
Please contact Secure ISS on 1300 769 460 for assistance.

