Ubiquiti Patches Critical UniFi Vulnerabilities
NEOSEC enrichment — no mirror of the original source
Ubiquiti has released updates to address seven critical vulnerabilities in UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS. CVE-2026-50746, CVSS score 10.0, is an improper access control issue in UniFi Connect Applicati
Source: SANS NewsBites. For licensing reasons NEOSEC Intel does not mirror the full text verbatim. Full body and expert context live with the original.
Editorial context in the original issue
The SANS NewsBites issue carries commentary by: Honan, Neely.
Linked advisories
- CVE-2026-55115Ubiquiti UniFi: Mehrere Schwachstellen
- CVE-2026-55115ui unifi_protect: Server-Side-Request-Forgery (SSRF)
- CVE-2026-55115ui unifi_protect: Server-Side-Request-Forgery (SSRF)
- CVE-2026-34908A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to…
- CVE-2026-34908Ubiquiti UniFi OS — Ubiquiti UniFi OS Improper Access Control Vulnerability
- CVE-2026-34908Ubiquiti UniFi OS Server: Mehrere Schwachstellen
- CVE-2026-34908ui enterprise_fortress_gateway_firmware: unzureichende Zugriffskontrolle
- CVE-2026-34910A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
- CVE-2026-34910Ubiquiti UniFi OS — Ubiquiti UniFi OS Improper Input Validation Vulnerability
- CVE-2026-34910ui enterprise_fortress_gateway_firmware: unzureichende Eingabevalidierung
- CVE-2026-50747ui unifi_talk_application: SQL-Injection
- CVE-2026-50747ui unifi_talk_application: SQL-Injection
- CVE-2026-34909A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system …
- CVE-2026-34909Ubiquiti UniFi OS — Ubiquiti UniFi OS Path Traversal Vulnerability
- CVE-2026-34909ui enterprise_fortress_gateway_firmware: Verzeichnisaufloesung (Path Traversal)
- CVE-2026-50746ui unifi_connect_application: unzureichende Zugriffskontrolle
- CVE-2026-50746ui unifi_connect_application: unzureichende Zugriffskontrolle
- CVE-2026-50748ui unifi_access: unzureichende Eingabevalidierung
- CVE-2026-50748ui unifi_access: unzureichende Eingabevalidierung
- CVE-2026-54400ui unifi_access: unzureichende Zugriffskontrolle
- CVE-2026-54400ui unifi_access: unzureichende Zugriffskontrolle
- CVE-2026-55116ui unifi_connect: unzureichende Zugriffskontrolle
- CVE-2026-55116ui unifi_connect: unzureichende Zugriffskontrolle
- CVE-2026-54402ui enterprise_firewall_core_firmware: unzureichende Eingabevalidierung
- CVE-2026-54402ui enterprise_firewall_core_firmware: unzureichende Eingabevalidierung
More on UniFi
Other advisories
- CVE-2026-20362mediumCisco Finesse, Unified CCE, Unified CCX: Schwachstelle ermöglicht Offenlegung von Informationen
- osv:MAL-2026-17566highMalicious code in unified-platform (npm)
- osv:CVE-2026-104019noneOS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution when running on Amazon SageMaker Unified Studio
- osv:CVE-2026-104434noneZebra before 8.0.0 Denial of Service via z_listunifiedreceivers RPC
- osv:CVE-2026-103241nonevllm-project vLLM Gemma4UnifiedParser gemma4.rs denial of service
- CVE-2026-95861mediumUbiquiti UniFi Gateways: Mehrere Schwachstellen ermöglichen Denial of Service
- CVE-2026-95861noneEin Angreifer mit Zugriff auf das Netzwerk könnte eine Schwachstelle aufgrund von unkontrollierter Rekursion in bestimmten UniFi-Gateway-Ger...
- CVE-2026-77558noneEin Angreifer mit Netzwerkzugriff könnte eine Schwachstelle für Lesezugriff außerhalb der Grenzen in bestimmten UniFi-Gateway-Geräten ausnut...
Other news entries
- Vulnerabilitybsi-cert-bund-wid2026-10-08Cisco Finesse, Unified CCE, Unified CCX: Schwachstelle ermöglicht Offenlegung von Informationen
- Vulnerabilitybsi-cert-bund-wid2026-09-23Ubiquiti UniFi Gateways: Mehrere Schwachstellen ermöglichen Denial of Service
- Newsthehackernews2026-09-16Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
- Newsncsc-nl2026-09-16NCSC-2026-0375 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Communications
- Vulnerabilitybsi-cert-bund-wid2026-09-10Insyde UEFI Firmware und Cisco UCS (UEFI Shell Secure Boot): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
- Vulnerabilitybsi-cert-bund-wid2026-09-09Insyde UEFI Firmware und Cisco UCS (UEFI Shell Secure Boot): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
- Vulnerabilitybsi-cert-bund-wid2026-09-01NetApp ActiveIQ Unified Manager für VMware vSphere (Glib, SQLite): Mehrere Schwachstellen
- Newsncsc-nl2026-08-27NCSC-2026-0330 [1.00] [M/H] Kwetsbaarheden verholpen in UniFi-producten van Ubiquiti
ID