Skip Navigation

August 27, 2026 |

Ubiquiti patches three critical UniFi vulnerabilities

Loading table of contents...

At a glance:

  • Ubiquiti released patches on August 26, 2026 for three maximum-severity vulnerabilities affecting UniFi Protect, UniFi OS, and UniFi Talk.

  • The vulnerabilities require little effort to exploit and do not depend on user interaction. Successful exploitation could allow unauthorized access to management functions, authentication bypass, or command execution on affected systems.

  • Identify relevant deployments, prioritize internet-facing systems, apply the updates released in Security Advisory Bulletin 067, and review admin access to affected platforms. 

Threat summary

On August 26, 2026, Ubiquiti released Security Advisory Bulletin 067 to address 22 vulnerabilities across its UniFi product portfolio.

Three critical vulnerabilities, CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554, received a CVSS score of 9.9 from Ubiquiti. The U.S. National Vulnerability Database (NVD) rates CVE-2026-77537 at 10.0. 

The vulnerabilities affect core components of the UniFi ecosystem that organizations use to manage networks, security systems, and communications infrastructure. UniFi OS provides centralized management for devices such as Dream Machines, Cloud Keys, gateways, and network video recorders. UniFi Protect manages security cameras and video storage, while UniFi Talk provides Voice over Internet Protocol (VoIP) services. These platforms are commonly deployed in business offices, schools, retail locations, and multi-site environments.

About the vulnerabilities:

  • CVE-2026-77537 affects UniFi Protect Application version 7.1.87 and earlier. The improper input validation vulnerability can allow an unauthenticated threat actor to compromise an affected device. Ubiquiti addressed the issue in UniFi Protect Application version 7.2.105.
  • CVE-2026-77550 is a CRLF injection vulnerability affecting UniFi OS. A threat actor with network access can exploit the flaw to bypass authentication on affected UniFi OS devices or instances. Fixes were released as part of Security Advisory Bulletin 067.
  • CVE-2026-77554 affects UniFi Talk Application version 5.2.7 and earlier. The vulnerability can allow command injection on the underlying host device by a threat actor with network access. The issue was fixed in UniFi Talk Application version 5.3.2.

The three vulnerabilities are easy to exploit and do not require user interaction. Depending on the affected product, a threat actor may only need network connectivity to the vulnerable service. If a UniFi management interface is accessible from the internet, a threat actor could attempt to exploit it directly from outside the organization.

If the service is only available internally, exploitation would first require access to the organization's network.

Analysis

These disclosures follow three separate UniFi OS vulnerabilities that were added to the U.S. Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog following confirmed attacks.

While the newly disclosed vulnerabilities have not been linked to exploitation, the earlier activity demonstrates that UniFi systems continue to attract attention from threat actors.

Organizations using UniFi OS, UniFi Protect, or UniFi Talk face the highest risk, particularly where UniFi consoles, Cloud Keys, Dream Machines, gateways, or network video recorders are reachable from untrusted networks or the internet.

Successful exploitation could give a threat actor access to the capabilities managed by the affected platform, for example:

  • In UniFi Protect environments, this could include surveillance management functions and access to camera-related systems

  • In UniFi Talk deployments, it could affect business phone services

  • For UniFi OS, the authentication bypass vulnerability could allow access to system management functions without valid credentials

The overall impact depends on the role of the affected device and what systems it administers.

Mitigations

Start by identifying any UniFi OS, UniFi Protect, and UniFi Talk deployments and confirming their software versions.

Prioritize systems that are exposed to the internet or provide centralized management for networking, surveillance, or communications services.

Apply the updates released in Security Advisory Bulletin 067, review remote access settings, and confirm that management interfaces are only accessible from trusted administrative networks.

ThreatRoundUp_SignUp_Simplifiedx2

Stay on top of emerging threats like this.

Sign up to receive a weekly roundup of our security intelligence feed. You'll be the first to know of emerging attack vectors, threats, and vulnerabilities. 

Sign up