Ubiquiti has released security updates to address three critical vulnerabilities that could allow unauthenticated remote attackers to compromise affected devices. The patches were issued on August 26, 2026, for flaws impacting the UniFi Protect Application, UniFi Talk Application, and UniFi OS.
One vulnerability, tracked as CVE-2026-77537, is an improper input validation issue within the UniFi Protect Application, a video surveillance management platform. This flaw could be exploited by unauthenticated attackers to compromise unpatched devices.
Another severe vulnerability, CVE-2026-77550, is a CRLF injection flaw affecting UniFi OS devices and instances. Ubiquiti stated that a malicious actor with network access could exploit this weakness to bypass authentication.
The third maximum-severity vulnerability, CVE-2026-77554, is a command injection flaw found in the UniFi Talk Application, a Voice over IP (VoIP) phone system. This issue also stems from improper input validation.
Ubiquiti has confirmed that these vulnerabilities can be exploited in low-complexity attacks that do not require user interaction. The company has not yet disclosed whether any of these specific flaws have been exploited in the wild prior to the release of the patches.
The necessary updates are included in UniFi Protect Application version 7.2.105 or later, UniFi Talk Application version 5.3.2 or later, and UniFi OS Server version 5.1.21 and earlier.
This round of patches follows a broader security update released on Thursday, August 22, 2026, which addressed 18 other critical-severity issues across various Ubiquiti products. These included the UniFi OS Server, UniFi Network Application, UniFi Protect AI Key, and a range of routers, gateways, NAS devices, and surveillance systems.
Threat intelligence data indicates over 100,000 UniFi OS instances are exposed online, though this figure may include historical scan results and does not differentiate between live systems, honeypots, or those already secured.
Ubiquiti products have been a target for state-backed hacking groups and cybercriminals, who have leveraged them to create large-scale botnets for concealing malicious activities. For instance, in February 2024, the FBI disrupted the Moobot botnet, which utilized Ubiquiti Edge OS routers to proxy traffic for the Russian Main Intelligence Directorate of the General Staff (GRU) in cyberespionage operations.
More recently, in June, the Cybersecurity and Infrastructure Security Agency (CISA) issued a directive requiring federal agencies to patch three other maximum-severity UniFi OS vulnerabilities within three days. These earlier flaws, patched in May, were actively being exploited in the wild and could be chained to achieve remote code execution with elevated privileges, as demonstrated by cybersecurity researchers.






