Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-77550

UniFi OS CRLF injection — authentication bypass

A CVSS 10.0 CRLF injection vulnerability in Ubiquiti's UniFi OS allows unauthenticated remote attackers to bypass authentication. Affects UniFi OS devices; patch version not yet publicly documented.

cat cve-2026-77550.json
Vendor
Ubiquiti
Product
UniFi OS (all devices running affected builds)
CVSS
10.0
EPSS (exploit probability)
N/A
Status
patched
Published

CVE-2026-77550 is a maximum-severity (CVSS 10.0) CRLF injection vulnerability in Ubiquiti’s UniFi OS — the underlying operating system running across UniFi network devices. Exploitation allows unauthenticated remote attackers to bypass authentication. The specific patched OS build version had not been publicly specified in initial disclosure; check the Ubiquiti security advisory bulletin for the definitive version requirement.

No known active exploitation at time of disclosure.

Check your UniFi OS console for available updates and apply the latest UniFi OS build immediately.