Ubiquiti patches three max severity security vulnerabilities

Ubiquiti has released urgent security patches for three maximum-severity vulnerabilities that can be exploited remotely without requiring any privileges. These flaws could allow threat actors, including state-backed hacking groups and cybercriminals, to compromise Ubiquiti devices used in a wide range of applications, from video surveillance management platforms to VoIP phone systems.

The first vulnerability, tracked as CVE-2026-77537, affects the UniFi Protect Application video surveillance management platform. It allows unauthenticated attackers to exploit an improper input validation weakness, which can lead to unauthorized access and control over affected devices. This means that even if a device has been configured with robust security settings, a malicious actor could still find a way in.

The second vulnerability, CVE-2026-77550, is a CRLF injection flaw that remote attackers can exploit to bypass authentication on UniFi OS devices or instances. According to Ubiquiti, this means that an attacker with access to the network could use this weakness to gain unauthorized access to sensitive systems and data. The company has patched this issue in UniFi OS Server 5.1.21 and earlier.

The third vulnerability, CVE-2026-77554, is a command injection security flaw stemming from improper input validation in the UniFi Talk Application Voice over IP (VoIP) phone system. This weakness could allow an attacker to inject malicious commands into affected devices, potentially leading to unauthorized access or even data breaches.

Ubiquiti has not disclosed whether any of these vulnerabilities were exploited in the wild before patching, but warns that they can be exploited in low-complexity attacks that don’t require user interaction. The company’s latest patches address these flaws in UniFi Protect Application 7.2.105 or later, UniFi Talk Application 5.3.2 or later, and UniFi OS Server 5.1.21 and earlier.

The fact that Ubiquiti has patched 18 more critical-severity security issues affecting a wide range of products is a concerning development for users. With the increasing number of Internet-exposed UniFi OS instances – currently tracked by threat intelligence company Censys at over 100,000 – it’s essential for organizations and individuals to ensure their systems are properly secured against these types of attacks.

In recent years, Ubiquiti products have been targeted by state-backed hacking groups and cybercriminals, who use them to build large-scale botnets that help conceal malicious activity. In February 2024, the FBI dismantled Moobot, a botnet of Ubiquiti Edge OS routers used by the Russian Main Intelligence Directorate of the General Staff (GRU) to proxy malicious traffic in cyberespionage attacks.

To avoid falling victim to these types of attacks, it’s crucial for users to keep their systems up-to-date with the latest security patches. Regularly monitoring system logs and network activity can also help detect potential security breaches early on. With the increasing sophistication of cyber threats, staying vigilant is more important than ever – especially when dealing with critical-severity vulnerabilities that can be exploited remotely without privileges.


Source: Bleeping Computer — 2026-08-26