Critical Vulnerabilities Found in Vertiv UPS Network Cards

Critical Vulnerabilities Found in Vertiv UPS Network Cards

First seen 9 Jun 2026, 20:59 UTC Facilitiesdivewww.claroty.comIndustrialcyber.CoScworld 86% similarity 72.8

Article Content

Browse articles
ThreatCluster

Team82 identified two critical vulnerabilities in Vertiv's Liebert IS-UNITY-DP network cards, both rated 9.8 on the CVSSv3 scale. The vulnerabilities, CVE-2025-46412 and CVE-2025-41426, allow for authentication bypass and remote code execution, posing significant risks to data centers reliant on these uninterruptible power supply (UPS) devices. Successful exploitation could enable attackers to disrupt power operations and execute arbitrary code, potentially affecting entire facilities. Vertiv has released firmware updates to mitigate these vulnerabilities, urging users to upgrade to specific versions. The vulnerabilities were disclosed on June 9, 2026, and are critical for organizations using Vertiv UPS systems.

Key Points: • Two critical vulnerabilities (CVE-2025-46412, CVE-2025-41426) found in Vertiv UPS network cards. • Exploits could allow attackers to disrupt power operations and execute arbitrary code. • Vertiv recommends immediate firmware updates to mitigate these vulnerabilities.

ThreatCluster AI

Timeline

2025-05-21
CVE-2025-46412 published
Authentication bypass vulnerability discovered in Vertiv's UPS network cards, allowing unauthorized access.
www.claroty.com
2025-05-21
CVE-2025-41426 published
Stack-based buffer overflow vulnerability identified, enabling remote code execution on affected devices.
www.claroty.com
2026-06-09
Vulnerabilities disclosed
Team82 published findings on critical vulnerabilities in Vertiv UPS network cards, urging immediate action.
Facilitiesdive
2026-06-09
Firmware updates recommended
Vertiv advised users to update to specific firmware versions to address the identified vulnerabilities.
Facilitiesdive

Community

Browse all →