Home · Briefs · CTI Weekly Summary — 2026-W26 (Jun 22 – Jun 28, 2026)
CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 — Ubiquiti UniFi OS Server: pre-auth RCE chain, exploited (CISA KEV)
From CTI Weekly Summary — 2026-W26 (Jun 22 – Jun 28, 2026) · published 2026-06-29
Three max-severity (CVSS 10.0) flaws in UniFi OS Server — improper access control and path traversal that bypass authentication and reach an unauthenticated RCE endpoint — were patched and KEV-listed with confirmed exploitation. UniFi controllers are common in DACH SME, education and public-sector branch networks; the management plane is frequently exposed. Patch and audit controller-account integrity.