Ubiquiti UniFi critical flaw (Bulletin 066)
Critical vulnerability in Ubiquiti UniFi products covered by Security Advisory Bulletin 066. CVSS 9.9. Part of a seven-CVE release batch headlined by a CVSS 10.0 command injection in UniFi Connect. Patch to 3.4.20 or later.
- Vendor
- Ubiquiti
- Product
- UniFi (see Bulletin 066 for affected versions)
- CVSS
- 9.9
- EPSS (exploit probability)
- 1.2%
- Status
- patched
- Published
CVE-2026-50748 is a CVSS 9.9 critical vulnerability in Ubiquiti UniFi products, disclosed in Security Advisory Bulletin 066 alongside six other critical CVEs. The lead issue in that bulletin is CVE-2026-50746 (CVSS 10.0, command injection in UniFi Connect ≤3.4.16), fixed in UniFi Connect 3.4.20.
For authoritative affected-version details and patch guidance, see the NVD record and Ubiquiti’s Bulletin 066.
No confirmed exploitation in the wild as of publication. Not on CISA KEV at time of writing.
Full coverage: Ubiquiti Patches Max-Severity UniFi Connect Command Injection.
