Skip to content
Ubiquiti Patches Three Critical Vulnerabilities in UniFi Products

Ubiquiti Patches Three Critical Vulnerabilities in UniFi Products

First seen 26 Aug 2026, 17:36 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 27, 2026 at 17:18 UTC

Ubiquiti has disclosed three critical vulnerabilities affecting its UniFi ecosystem, all published on 2026-08-26. These vulnerabilities, tracked as CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554, allow unauthenticated attackers to exploit improper input validation and CRLF injection flaws. Attackers with network access can execute arbitrary commands, bypass authentication, and gain full control over affected devices without needing privileges. Ubiquiti has released patches for these vulnerabilities, urging immediate updates to affected systems, including UniFi Protect Application, UniFi Talk Application, and UniFi OS Server. The vulnerabilities are rated with a CVSS score of 10.0, indicating critical severity. There is currently no evidence of exploitation in the wild, but the potential for remote attacks remains high. Ubiquiti's advisory highlights the urgency for users to secure their systems against these flaws.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 44d ago How this analysis works

Timeline

2026-08-26
Ubiquiti discloses critical vulnerabilities
Three critical vulnerabilities were published, allowing unauthenticated remote access to UniFi products.
Bleepingcomputer
2026-08-26
Patches released for vulnerabilities
Ubiquiti released updates for UniFi Protect Application, UniFi Talk Application, and UniFi OS Server to address the vulnerabilities.
Cybernews
2026-08-26
CVE details published
CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554 were published, detailing critical flaws in Ubiquiti products.
Cybersecuritynews
2026-08-26
CVE-2026-77550 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-26
CVE-2026-77554 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-26
CVE-2026-77537 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (20)

Following this threat?

Track Ubiquiti and CVE-2026-77537 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed