ctipilot.ch

Ubiquiti UniFi ecosystem: 22 CVEs in one bulletin, three at CVSS 10.0 — unauthenticated CRLF-injection auth bypass, and unauthenticated command injection in UniFi Protect and UniFi Talk

cve · CVE-2026-77550

Coverage timeline
1
first 2026-08-28 → last 2026-08-28
Peak priority
high
1 high
Sources cited
3
3 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
2
see Related entities below
ATT&CK techniques
2
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques
Affected products
Ubiquiti UniFi AccessUbiquiti UniFi ConnectUbiquiti UniFi Enterprise Audio/Video BridgeUbiquiti UniFi NetworkUbiquiti UniFi OS ServerUbiquiti UniFi ProtectUbiquiti UniFi Talk

ATT&CK techniques

2 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-28/ubiquiti-unifi-bulletin-067-22-cves-three-cvss10 · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-28/ubiquiti-unifi-bulletin-067-22-cves-three-cvss10 · ATT&CK page ↗

Persistence TA0003

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-28/ubiquiti-unifi-bulletin-067-22-cves-three-cvss10 · ATT&CK page ↗

Privilege Escalation TA0004

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-28/ubiquiti-unifi-bulletin-067-22-cves-three-cvss10 · ATT&CK page ↗

Stealth TA0005

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-28/ubiquiti-unifi-bulletin-067-22-cves-three-cvss10 · ATT&CK page ↗

Story timeline

  1. 2026-08-28Ubiquiti UniFi ecosystem: 22 CVEs in one bulletin, three at CVSS 10.0 — unauthenticated CRLF-injection auth bypass, and unauthenticated command injection in UniFi Protect and UniFi Talk
    trending-vulnerabilitiesUbiquiti's August bulletin carries three separate unauthenticated maximum-severity flaws across its OS, video and telephony product lines in one release

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • community.ui.com1 (33%)
  • heise.de1 (33%)
  • security-hub.ncsc.admin.ch1 (33%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Ubiquiti UniFi ecosystem: 22 CVEs in one bulletin, three at CVSS 10.0 — unauthenticated CRLF-injection auth bypass, and unauthenticated command injection in UniFi Protect and UniFi Talk (1)

2026-08-28 · view entry permalink →

Ubiquiti UniFi ecosystem: 22 CVEs in one bulletin, three at CVSS 10.0 — unauthenticated CRLF-injection auth bypass, and unauthenticated command injection in UniFi Protect and UniFi Talk

NCSC Switzerland's Cyber Security Hub published an advisory on 2026-08-27 transcribing Ubiquiti's Security Advisory Bulletin 067: 22 CVEs across the UniFi OS/Protect/Talk/Access/Network/Connect ecosystem, many at maximum severity. The three CVSS 10.0 entries are CVE-2026-77550 (authentication bypass via CRLF injection in UniFi OS devices), CVE-2026-77537 (unauthenticated command injection in UniFi Protect), and CVE-2026-77554 (unauthenticated command injection in UniFi Talk). A further ten CVEs score 9.9–9.8 (CVSS 3.1), spanning authenticated command injection in UniFi Access/Protect, privilege escalation via improper access control in UniFi OS/UniFi Protect AI Key, and unauthenticated command injection in the UniFi Enterprise Audio/Video Bridge. All require only network access to UniFi OS management interfaces or applications; the unauthenticated entries need no privilege at all, while the authenticated command-injection entries need low or high privilege depending on the flaw.

Vendor patches are available for the full set — per Heise Security's reporting: UniFi OS Server 5.1.37, UniFi Protect 7.2.105, UniFi Talk 5.3.2, UniFi Access 4.3.5, UniFi Network 10.5.67 (Heise Security, 2026-08-27). NCSC-CH records current exploitation status as unknown for this batch: "successful exploitation could allow network-adjacent attackers to completely compromise affected devices, leading to full system takeover via authentication bypass, command injection, or privilege escalation" (NCSC Switzerland Cyber Security Hub, 2026-08-27) — but Heise notes historical context that argues against reading "unknown" as "safe": Ubiquiti UniFi OS vulnerabilities from a May 2026 patch cycle were already under criminal attack by the end of June 2026, so a comparably fast exploitation timeline for this batch should be actively watched for rather than assumed absent.

UniFi is heavily deployed in SME and public-sector network, access-control and video-surveillance infrastructure across Europe, and its product breadth — OS management plane, physical access control, video surveillance, telephony — means this single bulletin touches several distinct functional surfaces in the same estate at once. Triage: in the absence of a published exploitation narrative, the defensible detection posture is process- and configuration-anomaly monitoring on UniFi OS management interfaces — unexpected administrative session creation not tied to a known operator login, and command-execution telemetry on the underlying host that does not correspond to a documented UniFi OS operation — since the vendor has not yet published the specific request patterns an exploit would use.

Successful exploitation could allow network-adjacent attackers to completely compromise affected devices, leading to full system takeover via authentication bypass, command injection, or privilege escalation.

NCSC Switzerland — Cyber Security Hub 2026-08-27
vulnerability28 Aug 05:55Zmulti-sourceOpen finding ↗