Medium Critical RCE Vulnerability in UniFi OS Allows Unauthorized Root Access
Article Content
- •UniFi OS Server vulnerabilities allow unauthenticated remote code execution.
- •Attackers can gain full root access with a single crafted HTTP request.
- •Thousands of organizations using UniFi OS Server are at risk.
A critical vulnerability chain in UniFi OS Server has been disclosed, allowing unauthenticated remote code execution (RCE) and full root access. The vulnerabilities include an authentication-gateway bypass, a path-traversal mismatch, and a command-injection sink in the package-update service. Attackers can exploit these flaws by sending a single crafted HTTP request, compromising affected devices without needing any credentials. This issue affects thousands of organizations using UniFi OS Server, which is the management platform for the UniFi family of products. Security Advisory Bulletin 064 has been issued, highlighting the severity of the vulnerabilities. Organizations are urged to assess their systems and apply necessary mitigations. No specific CVEs have been mentioned yet, but the implications are significant for cybersecurity across affected sectors.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…