Ubiquiti Issues Urgent Security Updates for UniFi OS After Discovery of Critical Flaws
Ubiquiti, a leading provider of network management and security solutions, has released emergency patches to fix seven critical vulnerabilities in its UniFi OS. Among these is a maximum-severity flaw that can be exploited by hackers to inject malicious commands into affected systems.
The vulnerability, tracked as CVE-2026-50746, affects the UniFi Connect Application, used by Ubiquiti customers to manage smart building operations and automate tasks such as controlling LED lighting systems and electric vehicle chargers. A malicious actor with network access could potentially use this flaw to execute a command injection on the host device, granting them unauthorized access.
Ubiquiti has instructed users to update their UniFi Connect app to version 3.4.20 or later to safeguard against potential attacks. The company’s prompt response is crucial, given that six of the seven vulnerabilities can be exploited in low-complexity attacks without requiring user interaction.
The affected applications include UniFi Talk, UniFi Access, and UniFi Protect, as well as Ubiquiti’s UniFi OS Server and various routers, gateways, NAS, and surveillance systems. The company has yet to confirm whether any of these vulnerabilities were exploited in the wild before being addressed.
A concerning aspect of this story is that threat intelligence company Censys reports over 100,000 UniFi OS instances exposed online, with nearly 50,000 IP addresses located in the United States. However, it’s unclear how many systems have been secured against these security flaws or are honeypots designed to detect malicious activity.
The discovery of these vulnerabilities is particularly alarming given Ubiquiti products’ history of being targeted by state-sponsored threat groups and cybercrime hacking groups. In recent years, hackers have used Ubiquiti devices to build botnets that conceal malicious activity, such as proxying traffic in cyberespionage attacks.
For instance, the FBI dismantled Moobot, a botnet composed of hacked Ubiquiti Edge OS routers used by Russia’s GRU for malicious purposes. Similarly, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned about critical vulnerabilities in Ubiquiti products being actively exploited, including one that was patched just a month prior to the warning.
To protect against such threats, it is essential for organizations and individuals to prioritize security updates and vulnerability patching. Regular testing of systems can help identify potential weaknesses before hackers do. As demonstrated by Bishop Fox’s detection script, which identified vulnerable instances in environments, proactive measures like these can significantly reduce the risk of successful attacks.
In light of this incident, we urge all Ubiquiti users to review their system configurations and ensure that they are running the latest software versions. Regular security audits and penetration testing can also help identify potential vulnerabilities and prevent unauthorized access to sensitive systems.
Source: Bleeping Computer — 2026-07-08