Ubiquiti has released emergency patches for three maximum-severity vulnerabilities that allow remote attackers to bypass authentication and compromise surveillance and VoIP systems.

  • Three maximum-severity flaws identified: CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554.
  • Attackers can exploit these remotely without user interaction or privileges.
  • Critical updates are required for UniFi Protect, UniFi Talk, and UniFi OS.

Networking giant Ubiquiti has issued critical security patches to address three newly discovered maximum-severity vulnerabilities. These flaws are particularly dangerous because they allow threat actors to execute remote attacks with low complexity and zero user interaction, potentially compromising entire network infrastructures.

Deep Dive into the Vulnerabilities

The first vulnerability, tracked as CVE-2026-77537, involves improper input validation within the UniFi Protect Application. This flaw could allow unauthenticated attackers to compromise video surveillance management platforms, posing a massive privacy risk.

The second flaw, CVE-2026-77550, is a CRLF injection vulnerability. This allows remote attackers to bypass authentication on UniFi OS devices, effectively granting them unauthorized access to the core operating system of the network hardware. Finally, CVE-2026-77554 is a command injection flaw discovered in the UniFi Talk Application, which manages Voice over IP (VoIP) phone systems.

Why This Matters

BozokMedia analysis shows that Ubiquiti products have become high-value targets for state-sponsored hacking groups. By compromising these devices, attackers can build massive, distributed botnets that mask their malicious traffic, making detection extremely difficult for security teams.

The ability for attackers to bypass authentication without any user interaction makes these vulnerabilities a top-tier priority for network administrators worldwide.

The scale of the risk is immense. According to threat intelligence firm Censys, over 100,000 UniFi OS instances are currently exposed to the public internet. Historically, the FBI has intervened in cases where Ubiquiti routers were used by Russian intelligence (GRU) to facilitate cyberespionage through the 'Moobot' botnet.

Required Security Updates

Affected ProductMinimum Secure Version
UniFi Protect Application7.2.105 or later
UniFi Talk Application5.3.2 or later
UniFi OS ServerPatch applied to 5.1.21 and earlier
Did You Know?: Hackers often use compromised network routers as 'proxies' to bounce their attacks, making it look like the attack is coming from a legitimate home or business network.

Frequently Asked Questions

1. Have these vulnerabilities been exploited in the wild?
While Ubiquiti has not confirmed active exploitation for these specific three flaws, they have warned that the complexity of an attack is very low.

2. How can I protect my network?
The only effective defense is to ensure all Ubiquiti hardware and software are running the latest patched versions immediately.