CTIPilot
← Back to Daily brief 2026-08-28
HIGHCVE-2026-77550 +2NATOA1vulnerability

Ubiquiti UniFi ecosystem: 22 CVEs in one bulletin, three at CVSS 10.0, unauthenticated CRLF-injection auth bypass, and unauthenticated command injection in UniFi Protect and UniFi Talk

Ubiquiti's August bulletin carries three separate unauthenticated maximum-severity flaws across its OS, video and telephony product lines in one release

Defender actions

  • Patch every UniFi OS Server, Protect, Talk, Access, Network and Connect deployment to the fixed releases now (UniFi OS Server 5.1.37, UniFi Protect 7.2.105, UniFi Talk 5.3.2, UniFi Access 4.3.5, UniFi Network 10.5.67 per Heise's reporting); three of the 22 flaws are unauthenticated, maximum-severity paths to full device takeover, and Ubiquiti's own May patch cycle was under criminal attack within roughly six weeks, so this batch should not be assumed safe on the strength of exploitation currently reading 'unknown'.

Analysis

NCSC Switzerland's Cyber Security Hub published an advisory on 2026-08-27 transcribing Ubiquiti's Security Advisory Bulletin 067: 22 CVEs across the UniFi OS/Protect/Talk/Access/Network/Connect ecosystem, many at maximum severity. The three CVSS 10.0 entries are CVE-2026-77550 (authentication bypass via CRLF injection in UniFi OS devices), CVE-2026-77537 (unauthenticated command injection in UniFi Protect), and CVE-2026-77554 (unauthenticated command injection in UniFi Talk). A further ten CVEs score 9.9–9.8 (CVSS 3.1), spanning authenticated command injection in UniFi Access/Protect, privilege escalation via improper access control in UniFi OS/UniFi Protect AI Key, and unauthenticated command injection in the UniFi Enterprise Audio/Video Bridge. All require only network access to UniFi OS management interfaces or applications; the unauthenticated entries need no privilege at all, while the authenticated command-injection entries need low or high privilege depending on the flaw.

Vendor patches are available for the full set, per Heise Security's reporting: UniFi OS Server 5.1.37, UniFi Protect 7.2.105, UniFi Talk 5.3.2, UniFi Access 4.3.5, UniFi Network 10.5.67 (Heise Security, 2026-08-27). NCSC-CH records current exploitation status as unknown for this batch: "successful exploitation could allow network-adjacent attackers to completely compromise affected devices, leading to full system takeover via authentication bypass, command injection, or privilege escalation" (NCSC Switzerland Cyber Security Hub, 2026-08-27), but Heise notes historical context that argues against reading "unknown" as "safe": Ubiquiti UniFi OS vulnerabilities from a May 2026 patch cycle were already under criminal attack by the end of June 2026, so a comparably fast exploitation timeline for this batch should be actively watched for rather than assumed absent.

UniFi is heavily deployed in SME and public-sector network, access-control and video-surveillance infrastructure across Europe, and its product breadth (OS management plane, physical access control, video surveillance, telephony) means this single bulletin touches several distinct functional surfaces in the same estate at once. Triage: in the absence of a published exploitation narrative, the defensible detection posture is process- and configuration-anomaly monitoring on UniFi OS management interfaces (unexpected administrative session creation not tied to a known operator login, and command-execution telemetry on the underlying host that does not correspond to a documented UniFi OS operation) since the vendor has not yet published the specific request patterns an exploit would use.

Cited evidence

Successful exploitation could allow network-adjacent attackers to completely compromise affected devices, leading to full system takeover via authentication bypass, command injection, or privilege escalation.

NCSC Switzerland, Cyber Security Hub 2026-08-27

Sources3

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.