Ubiquiti has released emergency patches for three maximum-severity vulnerabilities that allow remote attackers to bypass authentication and compromise surveillance and VoIP systems.
- Three maximum-severity flaws identified: CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554.
- Attackers can exploit these remotely without user interaction or privileges.
- Critical updates are required for UniFi Protect, UniFi Talk, and UniFi OS.
Networking giant Ubiquiti has issued critical security patches to address three newly discovered maximum-severity vulnerabilities. These flaws are particularly dangerous because they allow threat actors to execute remote attacks with low complexity and zero user interaction, potentially compromising entire network infrastructures.
Deep Dive into the Vulnerabilities
The first vulnerability, tracked as CVE-2026-77537, involves improper input validation within the UniFi Protect Application. This flaw could allow unauthenticated attackers to compromise video surveillance management platforms, posing a massive privacy risk.
The second flaw, CVE-2026-77550, is a CRLF injection vulnerability. This allows remote attackers to bypass authentication on UniFi OS devices, effectively granting them unauthorized access to the core operating system of the network hardware. Finally, CVE-2026-77554 is a command injection flaw discovered in the UniFi Talk Application, which manages Voice over IP (VoIP) phone systems.
Why This Matters
BozokMedia analysis shows that Ubiquiti products have become high-value targets for state-sponsored hacking groups. By compromising these devices, attackers can build massive, distributed botnets that mask their malicious traffic, making detection extremely difficult for security teams.
The ability for attackers to bypass authentication without any user interaction makes these vulnerabilities a top-tier priority for network administrators worldwide.
The scale of the risk is immense. According to threat intelligence firm Censys, over 100,000 UniFi OS instances are currently exposed to the public internet. Historically, the FBI has intervened in cases where Ubiquiti routers were used by Russian intelligence (GRU) to facilitate cyberespionage through the 'Moobot' botnet.
Required Security Updates
| Affected Product | Minimum Secure Version |
|---|---|
| UniFi Protect Application | 7.2.105 or later |
| UniFi Talk Application | 5.3.2 or later |
| UniFi OS Server | Patch applied to 5.1.21 and earlier |
Frequently Asked Questions
1. Have these vulnerabilities been exploited in the wild?
While Ubiquiti has not confirmed active exploitation for these specific three flaws, they have warned that the complexity of an attack is very low.
2. How can I protect my network?
The only effective defense is to ensure all Ubiquiti hardware and software are running the latest patched versions immediately.