• News/
  • bleepingcomputer-20260522120042

Ubiquiti patches three max severity UniFi OS vulnerabilities

BleepingComputer
·
Sergiu Gatlan
·
Published May 22, 2026
·
Updated

Ubiquiti has released security updates to patch three maximum severity vulnerabilities in UniFi OS that can be exploited by remote attackers without privileges. UniFi OS is a unified operating system that powers UniFi Consoles and helps manage IT infrastructure, including networking, security, and other services, as well as UniFi applications such as UniFi Network, UniFi Protect, UniFi Access, UniFi Talk, and UniFi Connect. The first flaw (CVE-2026-34908) enables attackers to make unauthorized changes to targeted systems by exploiting an Improper Access Control weakness in UniFi OS, while the second (CVE-2026-34909) allows them to access files on the underlying system by abusing a Path Traversal vulnerability, which could be manipulated to access an underlying account. A third maximum severity security issue (CVE-2026-34910) makes it possible for malicious actors to launch a command injection attack after gaining network access by exploiting an Improper Input Validation vulnerability. On Thursday, Ubiquiti also patched a second critical command injection flaw (CVE-2026-33000) and a high-severity information disclosure (CVE-2026-34911), both affecting Unifi OS devices. Ubiquiti has yet to disclose whether any of the five vulnerabilities were exploited in the wild before disclosure, but shared that they can be exploited in low-complexity attacks and were reported through its HackerOne bug bounty program. At the moment, threat intelligence company Censys is tracking nearly 100,...

Read full article

Affected Software

3 affected components
Ubiquiti UniFi OS
Ubiquiti UniFi Network Application
Ubiquiti AirOS
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the patching of three maximum severity vulnerabilities in Ubiquiti's UniFi OS.

2

What security implications are discussed?

The vulnerabilities can be exploited by remote attackers without privileges, posing a significant security risk.

3

What products or software are affected?

The affected products include Ubiquiti UniFi OS, Ubiquiti UniFi Network Application, and Ubiquiti AirOS.

4

Who is affected by these vulnerabilities?

Users of Ubiquiti UniFi OS and its associated applications are at risk due to these vulnerabilities.

5

What action has Ubiquiti taken in response to these vulnerabilities?

Ubiquiti has released security updates to patch the identified vulnerabilities in UniFi OS.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203