Ubiquiti Patches Critical Vulnerabilities, Urgent Action Required for Millions of Devices
Ubiquiti has released critical patches for three maximum-severity vulnerabilities that can be exploited remotely by attackers without any privileges. The flaws affect devices running UniFi Protect Application, UniFi Talk Application, and UniFi OS Server, putting millions of users at risk.
The first vulnerability (CVE-2026-77537) allows unauthenticated attackers to compromise unpatched devices by exploiting an improper input validation weakness in the UniFi Protect Application video surveillance management platform. This means that even if you’re not logged in or don’t have any credentials, a malicious actor can still access your device.
The second vulnerability (CVE-2026-77550) is a CRLF injection flaw that remote attackers without privileges can exploit to bypass authentication on UniFi OS devices or instances. According to Ubiquiti, an attacker with access to the network could use this vulnerability to gain unauthorized access to sensitive areas of these systems.
The third maximum severity vulnerability patched today is a command injection security flaw (CVE-2026-77554) stemming from improper input validation in the UniFi Talk Application Voice over IP (VoIP) phone system. This allows attackers to execute malicious commands, potentially leading to further vulnerabilities or even full control over the device.
Ubiquiti has not disclosed whether any of these security vulnerabilities were exploited in the wild before patching, but warns that they can be exploited in low-complexity attacks that don’t require user interaction. The company also notes that these flaws can be chained together to achieve more severe outcomes, such as remote code execution with elevated privileges.
The discovery of these critical vulnerabilities is not an isolated incident. Ubiquiti has been a favorite target for state-backed hacking groups and cybercriminals in recent years, who have used their products to build large-scale botnets that hide malicious activity. For example, the FBI dismantled Moobot, a botnet of Ubiquiti Edge OS routers used by Russian threat actors, just last year.
With over 100,000 UniFi OS instances exposed online, as tracked by Censys, it’s essential for users to take immediate action and ensure their devices are patched. While there’s no clear indication of how many devices are at risk or have already been secured against these flaws, the potential consequences of a successful attack are dire.
To protect yourself, we recommend taking the following steps:
* Immediately update your UniFi Protect Application, UniFi Talk Application, and UniFi OS Server to the latest version.
* Verify that all connected devices are patched and up-to-date.
* Conduct regular vulnerability scans to identify any potential security issues.
* Be cautious of unsolicited emails or messages claiming to be from Ubiquiti – they could be phishing attempts.
By taking these precautions, you can significantly reduce the risk of falling victim to a critical vulnerability attack. Remember, cybersecurity is an ongoing process that requires constant vigilance and attention to detail.
Source: Bleeping Computer — 2026-08-26