Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

Ubiquiti

Vulnerabilities in Ubiquiti's UniFi product line — the switches, gateways, and access points that make up the physical layer of a lot of small businesses, campuses, and prosumer networks, often deployed once and rarely touched again.

8 CVEs1 articlesRSS
CVEs
CVE-2026-50746
[ CRITICAL ]CVSS 10.0EPSS 1.7%patched

Ubiquiti UniFi Connect command injection (Bulletin 066)

Improper access control in Ubiquiti UniFi Connect ≤3.4.16 lets an attacker with network access execute command injection on the host device. CVSS 10.0. Fixed in 3.4.20.

Ubiquiti / UniFi Connect (3.4.16 and earlier)
CVE-2026-50747
[ CRITICAL ]CVSS 9.9EPSS 0.5%patched

Ubiquiti UniFi critical flaw (Bulletin 066)

Critical vulnerability in Ubiquiti UniFi products covered by Security Advisory Bulletin 066. CVSS 9.9. Part of a seven-CVE release batch headlined by a CVSS 10.0 command injection in UniFi Connect. Patch to 3.4.20 or later.

Ubiquiti / UniFi (see Bulletin 066 for affected versions)
CVE-2026-50748
[ CRITICAL ]CVSS 9.9EPSS 1.6%patched

Ubiquiti UniFi critical flaw (Bulletin 066)

Critical vulnerability in Ubiquiti UniFi products covered by Security Advisory Bulletin 066. CVSS 9.9. Part of a seven-CVE release batch headlined by a CVSS 10.0 command injection in UniFi Connect. Patch to 3.4.20 or later.

Ubiquiti / UniFi (see Bulletin 066 for affected versions)
CVE-2026-54400
[ CRITICAL ]CVSS 9.1EPSS 0.5%patched

Ubiquiti UniFi Access improper access control (Bulletin 066)

Improper access control in Ubiquiti UniFi Access lets a network attacker with existing high privileges escalate on the host device. CVSS 9.1. Fixed in the patch release accompanying Bulletin 066.

Ubiquiti / UniFi Access
CVE-2026-34908
[ CRITICAL ]CVSS 10.0EPSS 85.2%kev

Ubiquiti UniFi OS Improper Access Control Vulnerability

Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.

Ubiquiti / UniFi OS
CVE-2026-34909
[ CRITICAL ]CVSS 10.0EPSS 63.9%kev

Ubiquiti UniFi OS Path Traversal Vulnerability

Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.

Ubiquiti / UniFi OS
CVE-2026-34910
[ CRITICAL ]CVSS 10.0EPSS 87.5%kev

Ubiquiti UniFi OS Improper Input Validation Vulnerability

Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.

Ubiquiti / UniFi OS
CVE-2010-5330
[ CRITICAL ]CVSS 9.8EPSS 34.6%kev

Ubiquiti AirOS Command Injection Vulnerability

Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.

Ubiquiti / AirOS
Articles