In a nutshell: Ubiquiti products are at risk from critical flaws that allow unauthenticated attackers to achieve complete system takeover, in some cases directly accessible from the internet.
Ubiquiti has patched 25 vulnerabilities in its UniFi products, including multiple with severity ratings of 9.9 and 10. Attackers with network access can gain complete control over routers, gateways, video surveillance and building automation systems without authentication.
Ubiquiti has released security updates for 25 vulnerabilities affecting routers, gateways, network video recorders, video surveillance and building control systems. The most critical issue lies in the UniFi Connect Application, a management software for intelligent building technology such as digital displays and charging stations. This flaw receives the maximum CVSS rating of 10.0. According to Ubiquiti, insufficient access controls allow a malicious actor with network access to execute command injection on the host device.
Multiple vulnerabilities in UniFi OS also reach critical scores of 9.9 points. In particular, the combined flaws CVE-2026-54402 (insufficient input validation) and CVE-2026-54403 (directory traversal with complete authentication bypass) allow unauthenticated attackers to gain full control over critical infrastructure components such as routers, cloud controllers and network video recorders. Particularly relevant for CISOs: thousands of these devices are directly accessible over the internet, meaning attackers do not need local network access.
Specialized modules also exhibit critical flaws. The UniFi Access software for door control contains command injection and privilege escalation vulnerabilities. In UniFi Talk (telephony), SQL injections enable administrative privilege escalation. The UniFi Protect video surveillance system is at risk from server-side request forgery and authentication bypasses, through which attackers can unauthorizedly access video streams and camera data.
The U.S. cybersecurity authority CISA warns that older Ubiquiti vulnerabilities have already been actively exploited within days of disclosure. Immediate deployment of available software updates is the only mitigation measure.
Source: www.it-daily.net · Published 10 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.