CVE-2026-21639: Command Injection
A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
airFiber AF60to a version that resolves this vulnerability.Fixed in 2.6.8 - Upgrade
Upgrade
airFiber AF60-XGto a version that resolves this vulnerability.Fixed in 1.2.3 - Upgrade
Upgrade
airMAX ACto a version that resolves this vulnerability.Fixed in 8.7.21 - Upgrade
Upgrade
airMAX Mto a version that resolves this vulnerability.Fixed in 6.3.24
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21639?
CVE-2026-21639 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2026-21639?
To fix CVE-2026-21639, update your Ubiquiti airMAX AC to version 8.7.21 or later, and airMAX M to version 6.3.23 or later.
Which products are affected by CVE-2026-21639?
CVE-2026-21639 affects Ubiquiti airMAX AC (version 8.7.20 and earlier), airMAX M (version 6.3.22 and earlier), airFiber AF60-XG (version 1.2.2 and earlier), and airFiber AF60 (version 2.6.7 and earlier).
What type of attack can CVE-2026-21639 facilitate?
CVE-2026-21639 can facilitate a remote code execution attack if exploited.
Can CVE-2026-21639 be exploited from outside the Wi-Fi range?
CVE-2026-21639 requires the attacker to be within the Wi-Fi range of the affected product to exploit the vulnerability.