Ubiquiti UniFi Critical Flaws Let Attackers Bypass Auth, Inject Commands
Key Takeaways Ubiquiti has issued patches for 21 critical vulnerabilities across its UniFi product ecosystem. Attackers could leverage these flaws to bypass authentication, inject commands, and gain...
Key Takeaways
- Ubiquiti has issued patches for 21 critical vulnerabilities across its UniFi product ecosystem.
- Attackers could leverage these flaws to bypass authentication, inject commands, and gain full control over affected devices.
- The vulnerabilities affect a wide range of UniFi products, including routers, cameras, access control systems, and cloud gateways.
- Many of these flaws carry CVSS scores up to 10.0 and require only network access for exploitation.
- Immediate updates are available and strongly recommended by Ubiquiti.
Ubiquiti has released a comprehensive security update addressing 21 critical vulnerabilities that span nearly its entire UniFi product suite. The networking giant has warned that these flaws, if chained together, could allow attackers with basic network access to circumvent authentication, execute arbitrary commands, and ultimately compromise control over various UniFi devices, from routers and cameras to access control systems and cloud gateways.
Table Of Content
This latest disclosure follows closely on the heels of Ubiquiti’s previous Security Advisory Bulletin 064, which patched three maximum-severity, actively exploited vulnerabilities in UniFi OS. Those earlier flaws were significant enough to warrant inclusion in CISA’s Known Exploited Vulnerabilities catalog. The recurring nature of these high-impact issues underscores that the extensive UniFi ecosystem, utilized by diverse entities including homes, enterprises, and managed service providers for network, security, access, and communication, remains a prime target for both security researchers and malicious actors.
Command Injection Vulnerabilities Addressed
A significant portion of the newly disclosed vulnerabilities stems from inadequate input validation, which could enable attackers to execute arbitrary commands on host devices. The UniFi Protect Application, a cornerstone of the video surveillance infrastructure, features some of the most critical entries. Notably, CVE-2026-77537 boasts a perfect 10.0 CVSS score and requires no prior privileges for exploitation, while CVE-2026-77533 only necessitates low-level network access.
Both CVE-2026-77537 and CVE-2026-77533 are resolved in UniFi Protect Application version 7.2.105. Similar command injection vulnerabilities were also identified and patched across other UniFi components. These include UniFi OS Server (now fixed in version 5.1.37), UniFi Network Application (update to 10.5.67), UniFi Access Application (patched in 4.3.5), UniFi Talk Application (version 5.3.2, which also addresses a 10.0-rated flaw), the UID Enterprise Agent (fixed in 1.62.1), and the UniFi Enterprise Audio/Video Bridge (updated to 1.0.11).
Credit for reporting several of these severe vulnerabilities goes to researchers Brandon Rossi and the team at Catchify Security, alongside independent contributors such as bugbunny.ai and Ben Koo.
Privilege Escalation and Authentication Bypass Vulnerabilities
Beyond command injection, the advisory also highlights several improper access control vulnerabilities. These flaws could permit low-privileged network attackers to escalate their permissions to full administrator control on UniFi OS devices. This category encompasses a broad range of hardware, including Cloud Keys, Network Video Recorders, Dream Machines, Dream Routers, Enterprise Fortress Gateways, and Cloud Gateways.
Patches for these privilege escalation issues are available across UniFi OS versions 5.1.31 through 5.1.37, with specific version requirements varying by device family. Furthermore, two critical authentication bypass vulnerabilities, CVE-2026-77549 and CVE-2026-77550, were identified. These exploit improper neutralization of CRLF sequences, allowing network-based attackers to completely circumvent login mechanisms. CVE-2026-77550 carries a maximum CVSS score of 10.0 and was reported by a research team at TurtleSec.
Additional privilege escalation vulnerabilities were found in the UniFi Connect Application, UniFi Connect Display Cast Pro, UniFi Access Application, and the UniFi Protect AI Key, an edge AI module designed for camera analytics.
Every vulnerability detailed in this latest disclosure carries a CVSS base score ranging from 8.2 to a perfect 10.0. The fact that most only require network reachability for successful exploitation makes any unpatched, internet-facing UniFi deployments extremely vulnerable. Given the historical context of active exploitation against UniFi OS earlier in 2026, security teams should treat these updates as an imperative rather than a routine maintenance task.
What You Should Do
- Ubiquiti is urging all customers to immediately update their UniFi products to the latest patched versions.
- Specifically, update UniFi Protect to 7.2.105, UniFi OS Server to 5.1.37, UniFi Network Application to 10.5.67, UniFi Access to 4.3.5, UniFi Talk to 5.3.2, UniFi Connect to 3.24.22, the UID Enterprise Agent to 1.62.1, UniFi Connect Display Cast Pro to 1.0.111, the Enterprise Audio/Video Bridge to 1.0.11, and the Protect AI Key to 2.2.6.
- For organizations utilizing UniFi OS on hardware like Cloud Keys, NVRs, NAS units, Dream Machines, or Dream Routers, it is crucial to verify that the device firmware aligns with the vendor’s most recent builds, as patch levels can differ across hardware families.
- As a best practice, isolate management interfaces of UniFi devices from direct public internet exposure.
- Enforce multi-factor authentication (MFA) for all administrative access, particularly in scenarios where complete restriction of access to management interfaces is not feasible.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.