Vulnerability Management

Ubiquiti patches 3 critical remote code execution vulnerabilities

Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges, based on information published by Bleeping Computer.

The vulnerabilities include improper input validation in the UniFi Protect Application (CVE-2026-77537), a CRLF injection flaw in UniFi OS devices (CVE-2026-77550), and a command injection flaw in the UniFi Talk Application (CVE-2026-77554). These issues allow unauthenticated attackers to compromise devices, bypass authentication, and execute commands. Ubiquiti has not disclosed if these vulnerabilities were exploited in the wild, but they can be exploited with low complexity and no user interaction. This follows a recent patch for 18 other critical-severity issues affecting a wide range of Ubiquiti products.

Threat actors have frequently targeted Ubiquiti devices to build botnets, as seen with the FBI's disruption of the Russian Moobot botnet. In June, CISA mandated federal agencies to secure systems against similar critical UniFi OS vulnerabilities that were actively exploited. The company has released updates for UniFi Protect Application 7.2.105 or later, UniFi Talk Application 5.3.2 or later, and UniFi OS Server 5.1.21 and earlier.

Source: Bleeping Computer

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds