2026-07-08NOTABLENCSC-NL flags Ubiquiti UniFi SAB-066: unauthenticated CVSS 10.0 command injection plus 24 more
Ubiquiti UniFi Talk authenticated SQL injection (CVSS 9.9), SAB-066
cve · CVE-2026-50747
Coverage
1
first 2026-07-08 → last 2026-07-08
Latest activity
2026-07-08
NCSC-NL flags Ubiquiti UniFi SAB-066: unauthenticated CVSS 10.0 command injection plus 24 more
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, telco · regions: europe
Sources cited
2
2 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-50747, newest first. Check the date before acting on an older one.
- Update UniFi Connect ≥ 3.4.20, Talk ≥ 5.2.2, Access ≥ 4.2.29, Protect ≥ 7.1.83 and UniFi OS ≥ 5.1.19; no interim mitigation is documented for any of the 25 CVEs.2026-07-08CVE-2026-50746 +5
- Segregate every UniFi management-plane interface (controller UI, Connect, Talk, Access) from general LAN/internet exposure regardless of patch state; several flaws need only network adjacency and no or low privilege.2026-07-08CVE-2026-50746 +5
Defender insights
What each entry about CVE-2026-50747 tells a defender to do, newest first.
Story timeline
Hunting pivots
Entries about Ubiquiti UniFi Talk authenticated SQL injection (CVSS 9.9), SAB-066 (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Ubiquiti UniFi Access command injection (CVSS 9.9), SAB-066×1
- Ubiquiti UniFi Connect unauthenticated command-injection RCE (CVSS 10.0), SAB-066×1
- Ubiquiti UniFi OS command injection (CVSS 9.9), SAB-066×1
- Ubiquiti UniFi OS path-traversal auth-bypass (CVSS 8.6), chainable, SAB-066×1
- Ubiquiti UniFi Protect SSRF privilege escalation (CVSS 9.9), SAB-066×1
Where this entity is cited
Source distribution
- advisories.ncsc.nl1 (50%)
- socradar.io1 (50%)