
Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges.
The first (tracked as CVE-2026-77537) lets unauthenticated attackers compromise unpatched devices by exploiting an improper input validation weakness in the UniFi Protect Application video surveillance management platform.
Ubiquiti also addressed a CRLF injection flaw (CVE-2026-77550) that remote attackers without privileges can exploit to bypass authentication on UniFi OS devices or instances.
“A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running CRLF Injection to bypass authentication to such UniFi OS devices or instances,” it explained.
The third maximum severity vulnerability patched today is a command injection security flaw (CVE-2026-77554) stemming from improper input validation in the UniFi Talk Application Voice over IP (VoIP) phone system.
The company addressed these flaws in UniFi Protect Application 7.2.105 or later, UniFi Talk Application 5.3.2 or later, and UniFi OS Server 5.1.21 and earlier.
Ubiquiti has yet to disclose whether any of these security vulnerabilities were exploited in the wild before patching, but shared that they can be exploited in low-complexity attacks that don’t require user interaction.
On Thursday, Ubiquiti patched 18 more critical-severity security issues affecting a wide range of products, from the company’s UniFi OS Server to the UniFi Network Application centralized network management platform, the UniFi Protect AI Key hardware edge-computing appliance, and a large selection of Ubiquiti routers, gateways, NAS, and surveillance systems.
Threat intelligence company Censys now tracks more than 100,000 UniFi OS instances exposed online, but there are no details on how many are honeypots or have already been secured against these security flaws. However, Censys data may also include historical scan results, which might not accurately reflect the number of Internet-exposed systems.

State-backed hacking groups and cybercriminals have often targeted Ubiquiti products in recent years, using them to build large-scale botnets that helped conceal the threat actors’ malicious activity.
For instance, in February 2024, the FBI dismantled Moobot, a botnet of Ubiquiti Edge OS routers used by the Russian Main Intelligence Directorate of the General Staff (GRU) to proxy malicious traffic in cyberespionage attacks.
More recently, in June, CISA mandated that federal agencies secure their systems within three days against three other max-severity UniFi OS vulnerabilities that had been patched one month earlier and were now actively being exploited in the wild.
As cybersecurity firm Bishop Fox later demonstrated, the flaws could be chained to achieve remote code execution with elevated privileges.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.


