Ubiquiti UniFi Flaws Enable Root Access
Coverage from BleepingComputer, TechTimes, and others

Ubiquiti’s UniFi ecosystem is facing multiple critical vulnerabilities spanning UniFi OS Server, UniFi Network Application, and related Connect, Talk, Access, and Protect products.
Reported impacts include unauthenticated command execution with root privileges, account takeover, and privilege escalation, while some UniFi management endpoints have reportedly remained publicly reachable. The vulnerabilities matter because UniFi systems can administer networks and physical-security functions, and prior exploitation activity suggests that exposed, unpatched deployments could be rapidly targeted.
The update sharpens the UniFi vulnerability story by confirming the UniFi OS Server exploit chain no longer works on version 5.0.8, while also adding a more specific count of seven critical vulnerabilities across the ecosystem. It also broadens the exposure framing by emphasizing the wider building-systems impact and continued risk from publicly reachable management interfaces.
The story now adds a separate CVSS 10.0 command-execution flaw affecting multiple UniFi product lines, broadening the set of critical issues beyond the previously highlighted UniFi OS Server and Network Application bugs. It also newly emphasizes active botnet exploitation risk and a detection script that can confirm presence of the attack path but not past compromise.
