Ubiquiti patches three max severity security vulnerabilities

Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges.

The first (tracked as CVE-2026-77537) lets unauthenticated attackers compromise unpatched devices by exploiting an improper input validation weakness in the UniFi Protect Application video surveillance management platform.

Ubiquiti also addressed a CRLF injection flaw (CVE-2026-77550) that remote attackers without privileges can exploit to bypass authentication on UniFi OS devices or instances.

“A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running CRLF Injection to bypass authentication to such UniFi OS devices or instances,” it explained.

The third maximum severity vulnerability patched today is a command injection security flaw (CVE-2026-77554) stemming from improper input validation in the UniFi Talk Application Voice over IP (VoIP) phone system.

The company addressed these flaws in UniFi Protect Application 7.2.105 or later, UniFi Talk Application 5.3.2 or later, and UniFi OS Server 5.1.21 and earlier.

Ubiquiti has yet to disclose whether any of these security vulnerabilities were exploited in the wild before patching, but shared that they can be exploited in low-complexity attacks that don’t require user interaction.

On Thursday, Ubiquiti patched 18 more critical-severity security issues affecting a wide range of products, from the company’s UniFi OS Server to the UniFi Network Application centralized network management platform, the UniFi Protect AI Key hardware edge-computing appliance, and a large selection of Ubiquiti routers, gateways, NAS, and surveillance systems.

Threat intelligence company Censys now tracks more than 100,000 UniFi OS instances exposed online, but there are no details on how many are honeypots or have already been secured against these security flaws. ​However, Censys data may also include historical scan results, which might not accurately reflect the number of Internet-exposed systems.

State-backed hacking groups and cybercriminals have often targeted Ubiquiti products in recent years, using them to build large-scale botnets that helped conceal the threat actors’ malicious activity.

For instance, in February 2024, the FBI dismantled Moobot, a botnet of Ubiquiti Edge OS routers used by the Russian Main Intelligence Directorate of the General Staff (GRU) to proxy malicious traffic in cyberespionage attacks.

More recently, in June, CISA mandated that federal agencies secure their systems within three days against three other max-severity UniFi OS vulnerabilities that had been patched one month earlier and were now actively being exploited in the wild.

As cybersecurity firm Bishop Fox later demonstrated, the flaws could be chained to achieve remote code execution with elevated privileges.

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Ubiquiti warns of new max severity UniFi OS vulnerability

CISA warns of max severity Ubiquiti flaws exploited in attacks

Hackers target WordPress sites in miniOrange auth bypass attacks

Citrix urges admins to patch new NetScaler flaws as soon as possible

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

Microsoft Teams now lets admins block external bots from meetings

ToxicPanda Android malware uses VPN permissions to block Google Play

Hackers target WordPress sites in miniOrange auth bypass attacks

Overdue a password health-check? Audit your Active Directory for free

See how AI is reshaping email attacks. Download the 2026 Kaseya Email Security Report.

Protect yourself from data brokers, scammers, and the next data breach with digital identities.

Discover why encryption and key management are critical for modern business.

Discover how least agency keeps your AI tools capable, controlled, and secure.

Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.