Digital.Nhs.Uk Active Exploitation of Critical Vulnerabilities in Lantronix and Ubiquiti Devices
Article Content
- •CISA confirmed active exploitation of CVE-2025-67038 in Lantronix devices.
- •Ubiquiti's vulnerabilities could allow attackers to gain full control of networks.
- •Federal agencies must patch these vulnerabilities by June 26, 2026.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation of critical vulnerabilities in Lantronix EDS5000-series devices and Ubiquiti's UniFi OS. The Lantronix vulnerability, CVE-2025-67038, allows unauthenticated command injection, impacting industrial automation systems. Ubiquiti's vulnerabilities, CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, enable remote code execution and could facilitate broader network breaches. CISA has ordered federal agencies to patch these vulnerabilities by June 26, 2026. The risks are heightened due to the critical roles these devices play in network infrastructure. Both vulnerabilities were added to CISA's Known Exploited Vulnerabilities catalog on June 23, 2026. The urgency is underscored by the potential for significant operational disruption in affected environments.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track Prestige, Apt28 and BlackEnergy in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Trellix Reports on Five Evasive Cyber Campaigns in 2026 Trellix's SecondSight Threat Hunting Report details five significant cyber campaigns from the first half of 2026, including APT28 and the Axios npm supply chain attack. Attackers exploited trusted infrastructures and employed advanced evasion techniques, such as using compromised government accounts and weaponizing…
Leaked Files Expose Russian Cyber Training for Military Operations Leaked documents reveal a structured training pipeline at Bauman Moscow State Technical University, aimed at preparing students for military cyber operations. The records indicate that graduates are funneled into GRU units linked to notorious hacking groups APT28 and Sandworm, known for espionage and sabotage…