Last Update: 09/22/2026 at 11:34 PM EST

Ubiquiti UniFi Flaws Enable Root Access

Coverage from BleepingComputer, TechTimes, and others

Ubiquiti UniFi Flaws Enable Root Access topic image

Ubiquiti’s UniFi ecosystem is facing multiple critical vulnerabilities spanning UniFi OS Server, UniFi Network Application, and related Connect, Talk, Access, and Protect products.

Reported impacts include unauthenticated command execution with root privileges, account takeover, and privilege escalation, while some UniFi management endpoints have reportedly remained publicly reachable. The vulnerabilities matter because UniFi systems can administer networks and physical-security functions, and prior exploitation activity suggests that exposed, unpatched deployments could be rapidly targeted.

Looking Back
112 Day Timeline
Mar 19Apr 9Apr 30May 21Jun 11Jul 2
History
07/23/2026

The update sharpens the UniFi vulnerability story by confirming the UniFi OS Server exploit chain no longer works on version 5.0.8, while also adding a more specific count of seven critical vulnerabilities across the ecosystem. It also broadens the exposure framing by emphasizing the wider building-systems impact and continued risk from publicly reachable management interfaces.

07/21/2026

The story now adds a separate CVSS 10.0 command-execution flaw affecting multiple UniFi product lines, broadening the set of critical issues beyond the previously highlighted UniFi OS Server and Network Application bugs. It also newly emphasizes active botnet exploitation risk and a detection script that can confirm presence of the attack path but not past compromise.

All Articles3 articles
Additional3 articles · CI Score below 45
BleepingComputer / Bill Toulas
6/8/2026 • Cybersecurity (Privacy-Relevant) • General
TechTimes / Chase Fiorini
7/8/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Sergiu Gatlan
3/19/2026 • Cybersecurity (Privacy-Relevant) • General