Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges. The first (tracked as CVE-2026-77537) lets unauthenticated attackers compromise unpatched devices by exploiting an improper input validation weakness in the UniFi Protect Application video surveillance management platform. Ubiquiti also addressed a CRLF injection flaw (CVE-2026-77550) that remote attackers without privileges can exploit to bypass authentication on UniFi OS devices or instances. "A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running CRLF Injection to bypass authentication to such UniFi OS devices or instances," it explained. The third maximum severity vulnerability patched today is a command injection security flaw (CVE-2026-77554) stemming from improper input validation in the UniFi Talk Application Voice over IP (VoIP) phone system. The company addressed these flaws in UniFi Protect Application 7.2.105 or later, UniFi Talk Application 5.3.2 or later, and UniFi OS Server 5.1.21 and earlier. Ubiquiti has yet to disclose whether any of these security vulnerabilities were exploited in the wild before patching, but shared that they can be exploited in low-complexity attacks that don't require user interaction. On Thursday, Ubiquiti patched 18 more critical-severity security issues affecting a wide range of products, from th...
Ubiquiti patches three max severity security vulnerabilities
BleepingComputer
·Sergiu Gatlan
·Published Aug 26, 2026
·Updated
Affected Software
3 affected components
Ubiquiti Unifi Protect Application<7.2.105
Ubiquiti UniFi OS
Ubiquiti UniFi Talk Application<5.3.2
Frequently Asked Questions
1
Which Ubiquiti products are affected by the maximum-severity flaws?
The vulnerabilities affect the UniFi Protect Application video surveillance platform, UniFi OS devices or instances, and the UniFi Talk Application VoIP phone system.
2
What access does an attacker need to exploit these vulnerabilities?
The flaws can be exploited remotely without privileges. For the UniFi OS CRLF injection issue, Ubiquiti says the attacker must have access to the network.
3
What security impact is associated with each CVE?
CVE-2026-77537 can allow unauthenticated attackers to compromise unpatched UniFi Protect devices. CVE-2026-77550 can bypass authentication on UniFi OS devices or instances, while CVE-2026-77554 is a command injection flaw in UniFi Talk.
4
Which releases address the issues?
Ubiquiti addressed the flaws in UniFi Protect Application 7.2.105 or later, UniFi Talk Application 5.3.2 or later, and UniFi OS Server 5.1.21 and earlier.