Ubiquiti Patches Critical UniFi Flaws — Some Rated CVSS 10.0

Ubiquiti has shipped urgent patches for multiple critical vulnerabilities across UniFi Connect, Talk, Access, Protect, and OS. These flaws could let attackers escalate privileges or execute arbitrary commands on affected devices.

Seven CVEs were disclosed. The most severe?

CVE-2026-50746 — a perfect 10.0 CVSS score. An improper access control bug in UniFi Connect Application lets an attacker with network access execute command injection on the host device. Affects versions 3.4.16 and earlier. Fixed in 3.4.20.

The others aren’t far behind:

  • CVE-2026-50747 (CVSS 9.9) — SQL injection flaws in UniFi Talk Application allowing privilege escalation. Fixed in version 5.2.2.
  • CVE-2026-50748 (CVSS 9.9) — Input validation vulnerability in UniFi Access Application enabling command injection. Fixed in 4.2.29.
  • CVE-2026-54400 (CVSS 9.1) — Improper access control in UniFi Access Application for privilege escalation. Fixed in 4.2.29.
  • CVE-2026-55115 (CVSS 9.9) — SSRF vulnerability in UniFi Protect Application. Fixed in 7.1.83.
  • CVE-2026-54402 (CVSS 9.9) and CVE-2026-55116 (CVSS 9.0) — Two bugs in UniFi OS, both allowing command injection or unauthorized device changes. Fixed in 5.1.19.

No evidence of exploitation yet. But last month CISA flagged three separate UniFi OS vulnerabilities (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910) as actively weaponized in the wild. Russian state actors have also been caught turning Ubiquiti routers into a botnet called MooBot, which law enforcement took down in early 2024.

If you’re running UniFi gear, patch now. These are the kinds of bugs attackers chain together for full network compromise.

References