<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
    <channel>
        <title><![CDATA[Security | Releases | Ubiquiti Community]]></title>
        <description><![CDATA[Security | Releases | Ubiquiti Community]]></description>
        <link>https://community.ui.com</link>
        <image>
            <url>https://community.ui.com/images/og-image.jpg</url>
            <title>Security | Releases | Ubiquiti Community</title>
            <link>https://community.ui.com</link>
        </image>
        <generator>Ubiquiti Community</generator>
        <lastBuildDate>Fri, 28 Aug 2026 15:39:03 GMT</lastBuildDate>
        <atom:link href="https://community.ui.com/rss/releases/Security/f3f45fa2-1784-4594-b48d-28baf317b208" rel="self" type="application/rss+xml"/>
        <pubDate>Fri, 28 Aug 2026 15:39:03 GMT</pubDate>
        <copyright><![CDATA[© 2026 Ubiquiti Inc. All rights reserved.]]></copyright>
        <item>
            <title><![CDATA[Security Advisory Bulletin 068]]></title>
            <description><![CDATA[<h2>Overview</h2><p>Published: August 26, 2026</p><p>Version: 1.0</p><p>Revision: 1.0</p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwitch to initiate a Remote Code Execution on such device.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>EdgeMAX EdgeSwitch (Version 1.12.1 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your EdgeMAX EdgeSwitch to Version 1.12.2 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.6 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77532 (Will Robertson)</p><p><strong>&nbsp;</strong></p><p><strong>Reference Links:</strong></p><p><a href="https://uisp.community.ui.com/releases/EdgeMAX-EdgeSwitch-1-12-2/d4a7218e-cd00-4df9-b838-1875ea33f3a6" rel="noopener noreferrer" target="_blank">https://uisp.community.ui.com/releases/EdgeMAX-EdgeSwitch-1-12-2/d4a7218e-cd00-4df9-b838-1875ea33f3a6</a></p>]]></description>
            <link>https://community.ui.com/releases/Security-Advisory-Bulletin-068-068/b95ea5e8-1a80-4ffc-ad42-625eae300cc9</link>
            <guid isPermaLink="false">b95ea5e8-1a80-4ffc-ad42-625eae300cc9</guid>
            <category><![CDATA[edgemax]]></category>
            <category><![CDATA[security]]></category>
            <dc:creator><![CDATA[UI-Marcus]]></dc:creator>
            <pubDate>Wed, 26 Aug 2026 08:33:42 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Security Advisory Bulletin 067]]></title>
            <description><![CDATA[<h2>Overview</h2><p><strong>Security Advisory Bulletin 067</strong></p><p>Published: August 26, 2026</p><p>Version: 1.0</p><p>Revision: 1.0</p><p>&nbsp;</p><p><strong>Summary 1 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UniFi Protect Application (Version 7.1.87 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Protect Application to Version 7.2.105 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.9 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77533 (Abdulaziz Almadhi | Catchify Security)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 2 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi OS Server (Version 5.1.21 and earlier)</p><p>Cloud Keys, Network Video Recorders, Enterprise Network Video Recorders, Enterprise Network Attached Storage, Network Attached Storage, Dream Machines, Enterprise Firewall Core, Dream Routers, Enterprise Fortress Gateway, Cloud Gateways, Dream Wall and Express 7 (Version 5.1.26 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi OS Server to Version 5.1.37 or later.</p><p>Update your Cloud Keys, Network Video Recorders, Enterprise Network Video Recorders, Enterprise Network Attached Storage, Dream Machines, Enterprise Firewall Core, Dream Routers, Enterprise Fortress Gateway, Cloud Gateways, Dream Wall and Express 7 to Version 5.1.31 or later.</p><p>Update your Network Attached Storage to Version 5.1.32 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.9 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE: </strong>CVE-2026-77534 (Abdulaziz Almadhi | Catchify Security)</p><p><strong>&nbsp;</strong></p><p><strong>&nbsp;</strong></p><p><strong>Summary 3 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Command Injection on an adopted device.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UniFi Network Application (Version 10.4.57 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Network Application to Version 10.5.67 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.1 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77535 (Mohammad Seet)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 4 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UniFi OS Server (Version 5.1.21 and earlier)</p><p>Cloud Keys, Network Video Recorders, Enterprise Network Video Recorders, Enterprise Network Attached Storage, Network Attached Storage, Dream Machines, Enterprise Firewall Core, Dream Routers, Enterprise Fortress Gateway, Cloud Gateways, Dream Wall and Express 7 (Version 5.1.26 and earlier)</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update your UniFi OS Server to Version 5.1.37 or later.</p><p>Update your Cloud Keys, Network Video Recorders, Enterprise Network Video Recorders, Enterprise Network Attached Storage, Dream Machines, Enterprise Firewall Core, Dream Routers, Enterprise Fortress Gateway, Cloud Gateways, Dream Wall and Express 7 to Version 5.1.31 or later.</p><p>Update your Network Attached Storage to Version 5.1.32 or later.</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.9 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77536 (bugbunny.ai)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 5 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UniFi Protect Application (Version 7.1.87 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Protect Application to Version 7.2.105 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>10.0 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77537 (bugbunny.ai)</p><p>&nbsp;</p><p><strong>&nbsp;</strong></p><p><strong>Summary 6 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to escalate privileges within the UniFi Connect Application.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UniFi Connect Application (Version 3.24.20 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Connect Application to Version 3.24.22 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>8.2 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L</a></p><p><strong>CVE: </strong>CVE-2026-77538 (Andrii Timofeev)</p><p><strong>Note</strong>: This CVE can be chained with other dependency vulnerabilities to escalate privileges on the host device.</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 7 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi OS Server (Version 5.1.21 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi OS Server to Version 5.1.37 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.1 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77539 (Yasser Bensellam)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 8 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi OS Server (Version 5.1.21 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi OS Server to Version 5.1.37 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.1 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77540 (xzyhellsing (Saidina Hikam))</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 9 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Network Application (Version 10.4.57 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Network Application to Version 10.5.67 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.1 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77541 (Griffin Francis &amp; Adrian Wood )</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 10 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UID Enterprise Agent (Version 1.61.8 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UID Enterprise Agent to Version 1.62.1 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.1 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77542 (Ben Koo (@kiddo_pwn))</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 11 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Access Application (Version 4.3.3 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Access Application to Version 4.3.5 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.9 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77543 (Brandon Rossi)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 12 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi OS Server (Version 5.1.21 and earlier)</p><p>Cloud Keys, Network Video Recorders, Enterprise Network Video Recorders, Enterprise Network Attached Storage, Network Attached Storage, Dream Machines, Enterprise Firewall Core, Dream Routers, Enterprise Fortress Gateway, Cloud Gateways, Dream Wall and Express 7 (Version 5.1.26 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi OS Server to Version 5.1.37 or later.</p><p>Update your Cloud Keys, Network Video Recorders, Enterprise Network Video Recorders, Enterprise Network Attached Storage, Dream Machines, Enterprise Firewall Core, Dream Routers, Enterprise Fortress Gateway, Cloud Gateways, Dream Wall and Express 7 to Version 5.1.31 or later.</p><p>Update your Network Attached Storage to Version 5.1.32 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.0 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77545 (arqblasta)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 13 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Access Application (Version 4.3.3 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Access Application to Version 4.3.5 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.9 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77546 (Brandon Rossi)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 14 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Access Application (Version 4.3.3 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Access Application to Version 4.3.5 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.9 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77547 (Brandon Rossi)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 15 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UniFi Protect Application (Version 7.1.87 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Protect Application to Version 7.2.105 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.9 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77548 (Brandon Rossi)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 16 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi OS Server (Version 5.1.21 and earlier)</p><p>Cloud Keys, Network Video Recorders, Enterprise Network Video Recorders, Enterprise Network Attached Storage, Network Attached Storage, Dream Machines, Enterprise Firewall Core, Dream Routers, Enterprise Fortress Gateway, Cloud Gateways, Dream Wall and Express 7 (Version 5.1.26 and earlier)</p><p>Express (Version 4.0.16 and earlier)</p><p><strong>&nbsp;&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi OS Server to Version 5.1.37 or later.</p><p>Update your Cloud Keys, Network Video Recorders, Enterprise Network Video Recorders, Enterprise Network Attached Storage, Dream Machines, Enterprise Firewall Core, Dream Routers, Enterprise Fortress Gateway, Cloud Gateways, Dream Wall and Express 7 to Version 5.1.31 or later.</p><p>Update your Network Attached Storage to Version 5.1.32 or later.</p><p>Update your Express to Version 4.0.17 or later.</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.0 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77549 (Griffin Francis &amp; Adrian Wood)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 17 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi OS Server (Version 5.1.21 and earlier)</p><p>Cloud Keys, Network Video Recorders, Enterprise Network Video Recorders, Enterprise Network Attached Storage, Network Attached Storage, Dream Machines, Enterprise Firewall Core, Dream Routers, Enterprise Fortress Gateway, Cloud Gateways, Dream Wall and Express 7 (Version 5.1.26 and earlier)</p><p>Express (Version 4.0.16 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi OS Server to Version 5.1.37 or later.</p><p>Update your Cloud Keys, Network Video Recorders, Enterprise Network Video Recorders, Enterprise Network Attached Storage, Dream Machines, Enterprise Firewall Core, Dream Routers, Enterprise Fortress Gateway, Cloud Gateways, Dream Wall and Express 7 to Version 5.1.31 or later.</p><p>Update your Network Attached Storage to Version 5.1.32 or later.</p><p>Update your Express to Version 4.0.17 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>10.0 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77550 (Tobia Righi (mastersplinter), Scott Curtis (syndrome_impostor), Calvin Star (Skelet4r), at TurtleSec)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 18 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Connect Display Cast Pro to escalate privileges on the device.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UniFi Connect Display Cast Pro (Version 1.0.108 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Connect Display Cast Pro to Version 1.0.111 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.0 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77551 (Andy Gill, ZephrSec Ltd)</p><p>&nbsp;</p><p><strong>Summary 19 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Video Bridge to execute a Command Injection on the device.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Enterprise Audio/Video Bridge (Version 1.0.10 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Enterprise Audio/Video Bridge to Version 1.0.11 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.8 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77552 (Ben Koo (@kiddo_pwn))</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 20 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Access Application (Version 4.3.3 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Access Application to Version 4.3.5 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.9 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77553 (Brandon Rossi)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 21 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Talk Application (Version 5.2.7 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Talk Application to Version 5.3.2 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>10.0 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77554 (Brandon Rossi)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 22 of 22</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on the device.</p><p><br></p><p><strong>Affected Products:</strong></p><p>UniFi Protect AI Key (Version 2.1.3 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Protect AI Key to Version 2.2.6 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.8 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: CVE-2026-77557 (Brandon Rossi)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Reference Links:</strong></p><p><a href="https://community.ui.com/releases/UniFi-Protect-Application-7-2-105/4fa06975-6aa3-4e3f-b7d5-8814e331d14c" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Protect-Application-7-2-105/4fa06975-6aa3-4e3f-b7d5-8814e331d14c</a></p><p><a href="https://community.ui.com/releases/UniFi-Network-Application-10-5-67/375288b9-a4b4-46f1-a19d-5c787d342c2b" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Network-Application-10-5-67/375288b9-a4b4-46f1-a19d-5c787d342c2b</a></p><p><a href="https://community.ui.com/releases/UniFi-Connect-Application-3-24-22/700ffcb9-9392-485a-b8a3-fbcfb532dbae" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Connect-Application-3-24-22/700ffcb9-9392-485a-b8a3-fbcfb532dbae</a></p><p><a href="https://community.ui.com/releases/UniFi-Access-Application-4-3-5/5893e0cb-b696-4d03-a154-9b77bfc9cf5a" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Access-Application-4-3-5/5893e0cb-b696-4d03-a154-9b77bfc9cf5a</a></p><p><a href="https://community.ui.com/releases/UniFi-Talk-Application-5-3-2/b71f6ef3-46e3-48e8-bbd8-f3fe1303b864" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Talk-Application-5-3-2/b71f6ef3-46e3-48e8-bbd8-f3fe1303b864</a></p><p><a href="https://community.ui.com/releases/UID-Enterprise-Agent-1-62-1/84c4d821-d10b-4852-9398-a1b9c2cc1c33" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UID-Enterprise-Agent-1-62-1/84c4d821-d10b-4852-9398-a1b9c2cc1c33</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Server-5-1-37/ca9003ca-2c3f-42e6-9a1c-0a4f8edc0854" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Server-5-1-37/ca9003ca-2c3f-42e6-9a1c-0a4f8edc0854</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Cloud-Keys-5-1-31/799661f9-444a-4870-80be-ea8185aec47c" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Cloud-Keys-5-1-31/799661f9-444a-4870-80be-ea8185aec47c</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Network-Video-Recorders-5-1-31/7a703038-6610-4ba7-a0df-9e65cc2b2bd3" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Network-Video-Recorders-5-1-31/7a703038-6610-4ba7-a0df-9e65cc2b2bd3</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Enterprise-Network-Video-Recorders-5-1-31/d0dc2173-557d-486f-9734-7da0ff55ab34" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Enterprise-Network-Video-Recorders-5-1-31/d0dc2173-557d-486f-9734-7da0ff55ab34</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Enterprise-Network-Attached-Storage-5-1-31/13a3cb28-6736-4eab-82cc-fdb222e259ae" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Enterprise-Network-Attached-Storage-5-1-31/13a3cb28-6736-4eab-82cc-fdb222e259ae</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Network-Attached-Storage-5-1-32/ac8f3320-6ca1-4770-ae06-50074050e4b4" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Network-Attached-Storage-5-1-32/ac8f3320-6ca1-4770-ae06-50074050e4b4</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Dream-Machines-5-1-31/43fabe07-77c5-42e9-ba67-2b87543e800a" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Dream-Machines-5-1-31/43fabe07-77c5-42e9-ba67-2b87543e800a</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Enterprise-Firewall-Core-5-1-31/70df1c30-3a3a-4304-9c9b-5ea64ad5f006" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Enterprise-Firewall-Core-5-1-31/70df1c30-3a3a-4304-9c9b-5ea64ad5f006</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Dream-Routers-5-1-31/ae1111a4-f32d-459b-9ede-169e50352b1d" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Dream-Routers-5-1-31/ae1111a4-f32d-459b-9ede-169e50352b1d</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Enterprise-Fortress-Gateway-5-1-31/0000f8df-12e4-4b2d-9ea7-6a57bd9e7790" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Enterprise-Fortress-Gateway-5-1-31/0000f8df-12e4-4b2d-9ea7-6a57bd9e7790</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Cloud-Gateways-5-1-31/c922a942-a986-4151-9c39-45fa687be497" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Cloud-Gateways-5-1-31/c922a942-a986-4151-9c39-45fa687be497</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Dream-Wall-5-1-31/ba488ae0-9e0e-4937-aa11-295fb67010fc" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Dream-Wall-5-1-31/ba488ae0-9e0e-4937-aa11-295fb67010fc</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Express-7-5-1-31/03b70993-400b-4306-ab63-7bb589dceda3" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Express-7-5-1-31/03b70993-400b-4306-ab63-7bb589dceda3</a></p><p><a href="https://community.ui.com/releases/UniFi-Connect-Display-Cast-Pro-1-0-111/b9eb3af9-ca85-4404-82aa-34275cf8d948" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Connect-Display-Cast-Pro-1-0-111/b9eb3af9-ca85-4404-82aa-34275cf8d948</a></p><p><a href="https://community.ui.com/releases/UniFi-Enterprise-Audio-Video-Bridge-1-0-11/f8cca748-2118-4446-b229-b83363f9b83d" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Enterprise-Audio-Video-Bridge-1-0-11/f8cca748-2118-4446-b229-b83363f9b83d</a></p><p><a href="https://community.ui.com/releases/UniFi-Protect-AI-Key-2-2-6/c8116136-a594-47a2-982e-9575ef9cc492" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Protect-AI-Key-2-2-6/c8116136-a594-47a2-982e-9575ef9cc492</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Express-4-0-17/89813804-9deb-4cd9-a5dc-f36f6c7514b4" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Express-4-0-17/89813804-9deb-4cd9-a5dc-f36f6c7514b4</a></p>]]></description>
            <link>https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9</link>
            <guid isPermaLink="false">fc4a3488-7c43-4628-8bab-f715e96dbfc9</guid>
            <category><![CDATA[unifi-gateway-cloudkey]]></category>
            <category><![CDATA[unifi-network]]></category>
            <category><![CDATA[unifi-access]]></category>
            <category><![CDATA[unifi-talk]]></category>
            <category><![CDATA[unifi-connect]]></category>
            <category><![CDATA[uid]]></category>
            <category><![CDATA[security]]></category>
            <category><![CDATA[unifi-protect]]></category>
            <dc:creator><![CDATA[UI-Marcus]]></dc:creator>
            <pubDate>Wed, 26 Aug 2026 08:26:14 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Security Advisory Bulletin 066]]></title>
            <description><![CDATA[<h2>Overview</h2><p>Updated: July 26, 2026</p><p>Published: July 2, 2026</p><p>Version: 1.1</p><p>Revision: 1.1</p><p>&nbsp;</p><p><strong>Summary 1 of 25</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UniFi Connect Application (Version 3.24.16 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Connect Application to Version 3.24.20 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>10.0 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: <strong>&nbsp;</strong><a href="https://www.cve.org/CVERecord?id=CVE-2026-50746" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-50746</strong></a><strong> </strong>(Duc Anh Nguyen (@heckintosh_))</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 2 of 25</strong></p><p>&nbsp;&nbsp;</p><p>A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Talk Application (Version 5.1.2 and earlier)</p><p><br></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Talk Application to Version 5.2.2 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.9 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong> </strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-50747" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-50747</strong></a> (Abdulaziz Almadhi | Catchify Security)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 3 of 25</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Access Application (Version 4.2.28 and earlier)</p><p><br></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Access Application to Version 4.2.29 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.9 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong>&nbsp;</strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-50748" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-50748</strong></a> (Abdulaziz Almadhi | Catchify Security)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 4 of 25</strong></p><p><strong>&nbsp;&nbsp;</strong></p><p>A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Access Application (Version 4.2.28 and earlier)</p><p><br></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Access Application to Version 4.2.29 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.1 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong> </strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-54400" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-54400</strong></a> (Abdulaziz Almadhi | Catchify Security)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 5 of 25</strong></p><p>&nbsp;</p><p>A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi OS Server, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCK, UCKP, UCK-Enterprise, UNVR, UNVR-Pro, UNVR-Instant, ENVR, ENVR-Core, UNVR-G2, UNVR-G2-Pro, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber (Version 5.1.15 and earlier)</p><p><br></p><p>UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 (Version 5.1.16 and earlier)</p><p><br></p><p>EF-Core (Version 5.1.18 and earlier)</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update your UniFi OS Server, UDM, UDM-Beast, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCK, UCKP, UCK-Enterprise, UNVR, UNVR-Pro, UNVR-Instant, ENVR, ENVR-Core, UNVR-G2, UNVR-G2-Pro, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber to Version 5.1.19 or later.</p><p><br></p><p>Update your UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 to Version 5.1.19 or later.</p><p><br></p><p>Update your EF-Core to Version 5.1.19 or later.</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>7.7 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong> </strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-54401" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-54401</strong></a> (Kerolos Sameh | oathnet.org)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 6 of 25</strong></p><p>&nbsp;</p><p>A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.</p><p><br></p><p><strong>Affected Products:</strong></p><p>UniFi OS Server, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCK, UCKP, UCK-Enterprise, UNVR, UNVR-Pro, UNVR-Instant, ENVR, ENVR-Core, UNVR-G2, UNVR-G2-Pro, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber (Version 5.1.15 and earlier)</p><p><br></p><p>UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 (Version 5.1.16 and earlier)</p><p><br></p><p>EF-Core (Version 5.1.18 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi OS Server, UDM, UDM-Beast, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCK, UCKP, UCK-Enterprise, UNVR, UNVR-Pro, UNVR-Instant, ENVR, ENVR-Core, UNVR-G2, UNVR-G2-Pro, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber to Version 5.1.19 or later.</p><p><br></p><p>Update your UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 to Version 5.1.19 or later.</p><p><br></p><p>Update your EF-Core to Version 5.1.19 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.9 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong>&nbsp;</strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-54402" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-54402</strong></a> (arqblasta)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 7 of 25</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS devices or instances.</p><p><strong>Affected Products:</strong></p><p>UniFi OS Server, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCK, UCKP, UCK-Enterprise, UNVR, UNVR-Pro, UNVR-Instant, ENVR, ENVR-Core, UNVR-G2, UNVR-G2-Pro, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber (Version 5.1.15 and earlier)</p><p><br></p><p>UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 (Version 5.1.16 and earlier)</p><p><br></p><p>EF-Core (Version 5.1.18 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi OS Server, UDM, UDM-Beast, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCK, UCKP, UCK-Enterprise, UNVR, UNVR-Pro, UNVR-Instant, ENVR, ENVR-Core, UNVR-G2, UNVR-G2-Pro, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber to Version 5.1.19 or later.</p><p><br></p><p>Update your UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 to Version 5.1.19 or later.</p><p><br></p><p>Update your EF-Core to Version 5.1.19 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>8.6 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong> </strong></a>&nbsp;<a href="https://www.cve.org/CVERecord?id=CVE-2026-54403" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-54403</strong></a> (Griffin Francis &amp; Adrian Wood)</p><p><strong>&nbsp;</strong></p><p><strong>Note</strong>: This CVE can be chained with other vulnerabilities to eliminate the requirement for low-privileged access.</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 8 of 25</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devices or instances.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi OS Server, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCK, UCKP, UCK-Enterprise, UNVR, UNVR-Pro, UNVR-Instant, ENVR, ENVR-Core, UNVR-G2, UNVR-G2-Pro, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber (Version 5.1.15 and earlier)</p><p><br></p><p>UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 (Version 5.1.16 and earlier)</p><p><br></p><p>EF-Core (Version 5.1.18 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi OS Server, UDM, UDM-Beast, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCK, UCKP, UCK-Enterprise, UNVR, UNVR-Pro, UNVR-Instant, ENVR, ENVR-Core, UNVR-G2, UNVR-G2-Pro, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber to Version 5.1.19 or later.</p><p><br></p><p>Update your UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 to Version 5.1.19 or later.</p><p><br></p><p>Update your EF-Core to Version 5.1.19 or later.</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>8.8 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong> </strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-54404" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-54404</strong></a> (Garett Kopcha (0x5t))</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 9 of 25</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Denial of Service (DoS) attack on the application.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UniFi Network Application (Version 10.3.58 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Network Application to Version 10.4.57 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>7.5 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong>&nbsp;</strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-54405" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-54405</strong></a> (Dries from UniHosted)</p><p>&nbsp;</p><p><strong>Summary 10 of 25</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalate write permission on the host device.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Network Application (Version 10.3.58 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Network Application to Version 10.4.57 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>8.7 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong> </strong></a>&nbsp;<a href="https://www.cve.org/CVERecord?id=CVE-2026-54406" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-54406</strong></a> (Garett Kopcha (0x5t))</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 11 of 25</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UniFi Protect Application (Version 7.1.77 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Protect Application to Version 7.1.83 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>8.6 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong> </strong></a>&nbsp;<a href="https://www.cve.org/CVERecord?id=CVE-2026-54407" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-54407</strong></a> (Abdulaziz Almadhi / Catchify Security Team)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 12 of 25</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Protect Application (Version 7.1.77 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Protect Application to Version 7.1.83 or later.</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>8.6 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong>&nbsp;</strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-54408" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-54408</strong></a> (Brandon Rossi)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 13 of 25</strong></p><p>&nbsp;</p><p>A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulnerability found in UniFi Protect Application to bypass authentication in UniFi Protect Cameras.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UniFi Protect Application (Version 7.1.77 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Protect Application to Version 7.1.83 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>7.5 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong>&nbsp;</strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-54409" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-54409</strong></a> (Michał Suda (klumz33))</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 14 of 25</strong></p><p>&nbsp;</p><p>A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to trigger actions in UniFi OS using that user's session.&nbsp;</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi OS Server, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCK, UCKP, UCK-Enterprise, UNVR, UNVR-Pro, UNVR-Instant, ENVR, ENVR-Core, UNVR-G2, UNVR-G2-Pro, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber (Version 5.1.15 and earlier)</p><p><br></p><p>UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 (Version 5.1.16 and earlier)</p><p><br></p><p>EF-Core (Version 5.1.18 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi OS Server, UDM, UDM-Beast, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCK, UCKP, UCK-Enterprise, UNVR, UNVR-Pro, UNVR-Instant, ENVR, ENVR-Core, UNVR-G2, UNVR-G2-Pro, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber to Version 5.1.19 or later.</p><p><br></p><p>Update your UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 to Version 5.1.19 or later.</p><p><br></p><p>Update your EF-Core to Version 5.1.19 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>7.5 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong>&nbsp;</strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-55110" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-55110</strong></a> (Andy Gill, ZephrSec Ltd)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 15 of 25</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Protect Floodlight devices to access files on the UniFi Protect Floodlight.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Protect Floodlight(Version 1.13.4 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Protect Floodlight to Version 1.13.6 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>7.5 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong>&nbsp;</strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-55111" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-55111</strong></a> (Logan Fernandez (enzyme0))</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 16 of 25</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, UDW, UDR, UDR7, UDR-5G, UCKP, UNVR, UNVR-Pro, UNVR-Instant, ENVR, ENVR-Core, UNVR-G2, UNVR-G2-Pro, UCG-Max, UCG-Industrial and UCG-Fiber (Version 5.1.15 and earlier)</p><p><br></p><p><strong>Mitigation:</strong></p><p>Update your UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, UDW, UDR, UDR7, UDR-5G, UCKP, UNVR, UNVR-Pro, UNVR-Instant, ENVR, ENVR-Core, UNVR-G2, UNVR-G2-Pro, UCG-Max, UCG-Industrial and UCG-Fiber to Version 5.1.19 or later.</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>7.5 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong>&nbsp;</strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-55112" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-55112</strong></a> (Brandon Rossi)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 17 of 25</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk Application to execute a Denial of Service (DoS) attack and bypass authentication in certain UniFi Talk API endpoints.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Talk Application (Version 5.1.2 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Talk Application to Version 5.2.2 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>7.5 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong>&nbsp;</strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-55113" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-55113</strong></a> (Duc Anh Nguyen (@heckintosh_))</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 18 of 25</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Network Application (Version 10.3.58 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Network Application to Version 10.4.57 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>8.8 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong>&nbsp;</strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-55114" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-55114</strong></a> (Corbett3000)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 19 of 25</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Protect Application (Version 7.1.77 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Protect Application to Version 7.1.83 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.9 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong>&nbsp;</strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-55115" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-55115</strong></a> (Brandon Rossi)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 20 of 25</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UDM, UDM-Beast, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber (Version 5.1.15 and earlier)</p><p><br></p><p>EF-Core (Version 5.1.18 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UDM, UDM-Beast, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, EF-Core,&nbsp;UDW, UDR, UDR7, UDR-5G, Express 7, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber to Version 5.1.19 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.0 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong>&nbsp;</strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-55116" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-55116</strong></a> (Joseph Semaan)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 21 of 25</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the host device.</p><p><strong>Affected Products:</strong></p><p><br></p><p>UniFi Access Application (Version 4.2.28 and earlier)</p><p><br></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Access Application to Version 4.2.29 or later.</p><p><br></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>8.6 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong>&nbsp;</strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-55117" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-55117</strong></a> (Brandon Rossi)</p><p>&nbsp;&nbsp;</p><p>&nbsp;</p><p><strong>Summary 22 of 25</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Network Application (Version 10.3.58 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Network Application to Version 10.4.57 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>8.3 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong>&nbsp;</strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-55118" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-55118</strong></a> (bs0xx)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 23 of 25</strong></p><p><strong>&nbsp;</strong></p><p>A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Talk Application (Version 5.1.2 and earlier)</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update your UniFi Talk Application to Version 5.2.2 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>8.1 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong>&nbsp;</strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-55119" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-55119</strong></a> (Abdulaziz Almadhi | Catchify Security)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 24 of 25</strong></p><p>&nbsp;</p><p>A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Application to escalate privileges on the host device.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Protect Application (Version 7.1.77 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Protect Application to Version 7.1.83 or later.</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>8.8 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong> </strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-56841" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-56841</strong></a> (Abdulaziz Almadhi | Catchify Security)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 25 of 25</strong></p><p>&nbsp;</p><p>A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privileges within UniFi Network Application after such access had been removed.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Network Application (Version 10.3.58 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UniFi Network Application to Version 10.4.57 or later.</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>7.5 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong> </strong></a><a href="https://www.cve.org/CVERecord?id=CVE-2026-56842" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-56842</strong></a> (BugBunny.ai)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Reference Links:</strong></p><p><br></p><p><a href="https://community.ui.com/releases/UniFi-Connect-Application-3-24-20/3e2cd403-d021-4d40-8e33-0007e9683d62" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Connect-Application-3-24-20/3e2cd403-d021-4d40-8e33-0007e9683d62</a></p><p><a href="https://community.ui.com/releases/UniFi-Talk-Application-5-2-2/f27dcd51-f51b-4bc9-9a7f-ecbb215ceeb1" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Talk-Application-5-2-2/f27dcd51-f51b-4bc9-9a7f-ecbb215ceeb1</a></p><p><a href="https://community.ui.com/releases/UniFi-Access-Application-4-2-29/63eac165-b7d4-4c43-8091-55ade3ec73c1" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Access-Application-4-2-29/63eac165-b7d4-4c43-8091-55ade3ec73c1</a></p><p><a href="https://community.ui.com/releases/UniFi-Network-Application-10-4-57/92694b29-fd78-4d52-906a-3211136610e2" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Network-Application-10-4-57/92694b29-fd78-4d52-906a-3211136610e2</a></p><p><a href="https://community.ui.com/releases/UniFi-Protect-Application-7-1-83/70e6c6a6-cd7f-43e6-87fc-4d70f0a1d9c6" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Protect-Application-7-1-83/70e6c6a6-cd7f-43e6-87fc-4d70f0a1d9c6</a></p><p><a href="https://community.ui.com/releases/UniFi-Protect-Floodlight-1-13-6/ff9550e4-5e40-473d-95f0-047de07e87dd" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Protect-Floodlight-1-13-6/ff9550e4-5e40-473d-95f0-047de07e87dd</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Dream-Machines-5-1-19/32c35941-c2b6-4fa2-9e63-09470bfb85f6" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Dream-Machines-5-1-19/32c35941-c2b6-4fa2-9e63-09470bfb85f6</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Enterprise-Firewall-Core-5-1-19/21263def-e96c-47e6-9a75-96293fcb84e0" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Enterprise-Firewall-Core-5-1-19/21263def-e96c-47e6-9a75-96293fcb84e0</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Enterprise-Fortress-Gateway-5-1-19/45d861a0-fd93-43ee-841e-033423b112a2" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Enterprise-Fortress-Gateway-5-1-19/45d861a0-fd93-43ee-841e-033423b112a2</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Enterprise-Network-Video-Recorders-5-1-19/ca291ead-bc98-4e8b-bc85-4ec03de3f77d" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Enterprise-Network-Video-Recorders-5-1-19/ca291ead-bc98-4e8b-bc85-4ec03de3f77d</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Network-Video-Recorders-5-1-19/0728e007-aedd-4664-a3a1-38661b36f9bb" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Network-Video-Recorders-5-1-19/0728e007-aedd-4664-a3a1-38661b36f9bb</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Cloud-Gateways-5-1-19/233f8d0a-9973-4e01-a51e-30713939b240" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Cloud-Gateways-5-1-19/233f8d0a-9973-4e01-a51e-30713939b240</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Cloud-Keys-5-1-19/44aabe56-c674-47f7-85f4-d483bb7c5bfe" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Cloud-Keys-5-1-19/44aabe56-c674-47f7-85f4-d483bb7c5bfe</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Dream-Wall-5-1-19/c33cde37-ac2e-4015-bcb6-39567448fc35" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Dream-Wall-5-1-19/c33cde37-ac2e-4015-bcb6-39567448fc35</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Network-Attached-Storage-5-1-19/553addc7-4444-4eed-b46f-b2ee1f5f2285" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Network-Attached-Storage-5-1-19/553addc7-4444-4eed-b46f-b2ee1f5f2285</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Dream-Routers-5-1-19/b9ae8a01-9415-496a-92b2-70aa784de65d" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Dream-Routers-5-1-19/b9ae8a01-9415-496a-92b2-70aa784de65d</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Express-7-5-1-19/71fbc82e-da12-43df-82a7-6cd5a316e867" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Express-7-5-1-19/71fbc82e-da12-43df-82a7-6cd5a316e867</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Server-5-1-19/05db58f8-3306-48dc-bbd8-6cb681046a6d" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Server-5-1-19/05db58f8-3306-48dc-bbd8-6cb681046a6d</a></p>]]></description>
            <link>https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc</link>
            <guid isPermaLink="false">984eceb3-49c8-4227-942d-671c289b3afc</guid>
            <category><![CDATA[unifi-gateway-cloudkey]]></category>
            <category><![CDATA[security]]></category>
            <category><![CDATA[unifi-protect]]></category>
            <category><![CDATA[unifi-network]]></category>
            <category><![CDATA[unifi-access]]></category>
            <category><![CDATA[unifi-talk]]></category>
            <category><![CDATA[unifi-connect]]></category>
            <category><![CDATA[unifi-drive]]></category>
            <dc:creator><![CDATA[UI-Marcus]]></dc:creator>
            <pubDate>Thu, 02 Jul 2026 05:26:20 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Security Advisory Bulletin 065]]></title>
            <description><![CDATA[<h2>Overview</h2><p>Published: Jun 10, 2026</p><p>Version: 1.0</p><p>Revision: 1.0</p><p>&nbsp;</p><p><strong>Summary 1 of 5</strong></p><p>&nbsp;</p><p>A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UID Enterprise Agent (Version 1.61.3 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update your UID Enterprise Agent&nbsp;to Version 1.61.4 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.9 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS</strong>: <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE</strong>: <a href="https://www.cve.org/CVERecord?id=CVE-2026-47367" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-47367</strong></a> (Abdulaziz Almadhi | Catchify Security)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 2 of 5</strong></p><p>&nbsp;</p><p>A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from such UniFi OS devices or instances.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCK, UCKP, UCK-Enterprise, UNVR, UNVR-Pro, UNVR-Instant, ENVR, ENVR-Core, UNVR-G2, UNVR-G2-Pro, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber (Version 5.1.12 and earlier)</p><p>UniFi OS Server (Version 5.0.8 and earlier)</p><p>UDM-Beast (Version 5.1.11 and earlier)</p><p>UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 (Version 5.1.10 and earlier)</p><p>Express (Version 4.0.14 and earlier)</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update your UniFi OS Server, UDM, UDM-Beast, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCK, UCKP, UCK-Enterprise, UNVR, UNVR-Pro, UNVR-Instant, ENVR, ENVR-Core, UNVR-G2, UNVR-G2-Pro, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber to Version 5.1.15 or later.</p><p>Update your UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 to Version 5.1.16 or later.</p><p>Update your Express to Version 4.0.15 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>8.6 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N</a></p><p><strong>CVE: </strong><a href="https://www.cve.org/CVERecord?id=CVE-2026-47368" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-47368</strong></a> (Brandon Rossi)</p><p><strong>&nbsp;</strong></p><p><strong>Note</strong>: This CVE can be chained with other vulnerabilities to eliminate the requirement for low-privileged access.</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 3 of 5</strong></p><p>&nbsp;</p><p>A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCK, UCKP, UCK-Enterprise, UNVR, UNVR-Pro, UNVR-Instant, ENVR, ENVR-Core, UNVR-G2, UNVR-G2-Pro, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber (Version 5.1.12 and earlier)</p><p>UniFi OS Server (Version 5.0.8 and earlier)</p><p>UDM-Beast (Version 5.1.11 and earlier)</p><p>UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 (Version 5.1.10 and earlier)</p><p>Express (Version 4.0.14 and earlier)</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update your UniFi OS Server, UDM, UDM-Beast, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCK, UCKP, UCK-Enterprise, UNVR, UNVR-Pro, UNVR-Instant, ENVR, ENVR-Core, UNVR-G2, UNVR-G2-Pro, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber to Version 5.1.15 or later.</p><p>Update your UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 to Version 5.1.16 or later.</p><p>Update your Express to Version 4.0.15 or later.</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.9 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE: </strong><a href="https://www.cve.org/CVERecord?id=CVE-2026-47369" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-47369</strong></a> (Brandon Rossi)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 4 of 5</strong></p><p>&nbsp;</p><p>A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCK, UCKP, UCK-Enterprise, UNVR, UNVR-Pro, UNVR-Instant, ENVR, ENVR-Core, UNVR-G2, UNVR-G2-Pro, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber (Version 5.1.12 and earlier)</p><p>UniFi OS Server (Version 5.0.8 and earlier)</p><p>UDM-Beast (Version 5.1.11 and earlier)</p><p>UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 (Version 5.1.10 and earlier)</p><p>Express (Version 4.0.14 and earlier)</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update your UniFi OS Server, UDM, UDM-Beast, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCK, UCKP, UCK-Enterprise, UNVR, UNVR-Pro, UNVR-Instant, ENVR, ENVR-Core, UNVR-G2, UNVR-G2-Pro, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber to Version 5.1.15 or later.</p><p>Update your UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 to Version 5.1.16 or later.</p><p>Update your Express to Version 4.0.15 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.9 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE: </strong><a href="https://www.cve.org/CVERecord?id=CVE-2026-47370" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-47370</strong></a> (Brandon Rossi)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 5 of 5</strong></p><p>&nbsp;</p><p>Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber (Version 5.1.12 and earlier)</p><p>UDM-Beast (Version 5.1.11 and earlier)</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update your UDM, UDM-Beast, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber to Version 5.1.15 or later.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>8.1 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a></p><p><strong>CVE: </strong><a href="https://www.cve.org/CVERecord?id=CVE-2026-48610" rel="noopener noreferrer" target="_blank"><strong>CVE-2026-48610</strong></a> (Duc Anh Nguyen (@heckintosh_))</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Reference Links:</strong></p><p><a href="https://community.ui.com/releases/UID-Enterprise-Agent-1-61-4/142f588d-a6f1-44a2-adad-b631d7fcc859" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UID-Enterprise-Agent-1-61-4/142f588d-a6f1-44a2-adad-b631d7fcc859</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Network-Attached-Storage-5-1-16/8342667f-08b5-4006-97d5-595593ea7e17" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Network-Attached-Storage-5-1-16/8342667f-08b5-4006-97d5-595593ea7e17</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Express-7-5-1-15/84641421-6507-48af-914f-c0cb5f704c76" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Express-7-5-1-15/84641421-6507-48af-914f-c0cb5f704c76</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Network-Video-Recorders-5-1-15/b208b498-7e6b-4ba2-8314-a1f8436e1746" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Network-Video-Recorders-5-1-15/b208b498-7e6b-4ba2-8314-a1f8436e1746</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Enterprise-Network-Video-Recorders-5-1-15/6d0b2652-08dd-46e9-9850-750e7cf46753" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Enterprise-Network-Video-Recorders-5-1-15/6d0b2652-08dd-46e9-9850-750e7cf46753</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Dream-Wall-5-1-15/353c7ec2-fb95-4820-89fa-1f04e4a7e574" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Dream-Wall-5-1-15/353c7ec2-fb95-4820-89fa-1f04e4a7e574</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Dream-Routers-5-1-15/2ba464cc-e812-40f5-8e73-20a55dc0ba55" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Dream-Routers-5-1-15/2ba464cc-e812-40f5-8e73-20a55dc0ba55</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Enterprise-Fortress-Gateway-5-1-15/e41884b0-04c6-44e4-89c5-a3f96c41e709" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Enterprise-Fortress-Gateway-5-1-15/e41884b0-04c6-44e4-89c5-a3f96c41e709</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Dream-Machines-5-1-15/5ed916bc-aa53-4618-81b4-d97d45590b8d" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Dream-Machines-5-1-15/5ed916bc-aa53-4618-81b4-d97d45590b8d</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Cloud-Keys-5-1-15/eef40b81-7b36-4dda-a76e-3086f0bbd68b" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Cloud-Keys-5-1-15/eef40b81-7b36-4dda-a76e-3086f0bbd68b</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Cloud-Gateways-5-1-15/37aeb9f3-c3a2-474d-ac9a-aa2ec7ecf417" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Cloud-Gateways-5-1-15/37aeb9f3-c3a2-474d-ac9a-aa2ec7ecf417</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Server-5-1-15/11843c60-7c4f-4263-9773-4c3df7168d07" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Server-5-1-15/11843c60-7c4f-4263-9773-4c3df7168d07</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Express-4-0-15/8821b99b-bc3e-49cd-88bb-1a348f2b2a90" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Express-4-0-15/8821b99b-bc3e-49cd-88bb-1a348f2b2a90</a></p>]]></description>
            <link>https://community.ui.com/releases/Security-Advisory-Bulletin-065-065/aa46a22b-fc43-4eae-9382-6fc8feda967a</link>
            <guid isPermaLink="false">aa46a22b-fc43-4eae-9382-6fc8feda967a</guid>
            <category><![CDATA[security]]></category>
            <category><![CDATA[unifi-gateway-cloudkey]]></category>
            <category><![CDATA[unifi-network]]></category>
            <category><![CDATA[unifi-protect]]></category>
            <category><![CDATA[unifi-drive]]></category>
            <category><![CDATA[unifi-access]]></category>
            <category><![CDATA[unifi-talk]]></category>
            <category><![CDATA[uid]]></category>
            <category><![CDATA[unifi-connect]]></category>
            <dc:creator><![CDATA[UI-Marcus]]></dc:creator>
            <pubDate>Wed, 10 Jun 2026 23:36:03 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Security Advisory Bulletin 064]]></title>
            <description><![CDATA[<h2>Overview</h2><p>Published: May 21, 2026</p><p>Updated: May 22, 2026</p><p>Version: 1.1</p><p>Revision: 1.1</p><p><strong>&nbsp;</strong></p><p><strong>Summary 1 of 5</strong></p><p>&nbsp;</p><p>A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi OS Server (Version 5.0.6 and earlier)</p><p><br></p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update your UniFi OS Server&nbsp;to Version 5.0.8 or later</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.1 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE: </strong><a href="https://www.cve.org/CVERecord?id=CVE-2026-33000" rel="noopener noreferrer" target="_blank">CVE-2026-33000</a> (V3rlust)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 2 of 5</strong></p><p>&nbsp;</p><p>A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UCG-Industrial (Version 5.0.13 and earlier)</p><p>UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber (Version 5.0.16 and earlier)</p><p>UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise (Version 5.0.17 and earlier)</p><p>UniFi OS Server (Version 5.0.6 and earlier)</p><p>UNVR-G2 and UNVR-G2-Pro (Version 5.1.11 and earlier)</p><p>UDM-Beast, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 (Version 5.1.8 and earlier)</p><p><br></p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update your UCG-Industrial to Version 5.1.12 or later.</p><p>Update your UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber to Version 5.1.12 or later.</p><p>Update your UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise to Version 5.1.12 or later.</p><p>Update your UniFi OS Server to Version 5.0.8 or later.</p><p>Update your UNVR-G2 and UNVR-G2-Pro to Version 5.1.12 or later.</p><p>Update your UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 to Version 5.1.10 or later.</p><p>Update your UDM-Beast 5.1.11 or later.</p><p><br></p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>10.0 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE: </strong><a href="https://www.cve.org/CVERecord?id=CVE-2026-34908" rel="noopener noreferrer" target="_blank">CVE-2026-34908</a> (Duc Anh Nguyen (@heckintosh_))</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 3 of 5</strong></p><p>&nbsp;</p><p>A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UCG-Industrial (Version 5.0.13 and earlier)</p><p>UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber (Version 5.0.16 and earlier)</p><p>UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise (Version 5.0.17 and earlier)</p><p>UniFi OS Server (Version 5.0.6 and earlier)</p><p>UNVR-G2 and UNVR-G2-Pro (Version 5.1.11 and earlier)</p><p>UDM-Beast, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 (Version 5.1.8 and earlier)</p><p>Express (Version 4.0.13 and earlier)</p><p><br></p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update your UCG-Industrial to Version 5.1.12 or later.</p><p>Update your UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber to Version 5.1.12 or later.</p><p>Update your UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise to Version 5.1.12 or later.</p><p>Update your UniFi OS Server to Version 5.0.8 or later.</p><p>Update your UNVR-G2 and UNVR-G2-Pro to Version 5.1.12 or later.</p><p>Update your UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 to Version 5.1.10 or later.</p><p>Update your UDM-Beast 5.1.11 or later.</p><p>Update your Express to Version 4.0.14 or later.</p><p><br></p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>10.0 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE: </strong><a href="https://www.cve.org/CVERecord?id=CVE-2026-34909" rel="noopener noreferrer" target="_blank">CVE-2026-34909</a> (Abdulaziz Almadhi | Catchify Security)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 4 of 5</strong></p><p>&nbsp;</p><p>A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UCG-Industrial (Version 5.0.13 and earlier)</p><p>UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber (Version 5.0.16 and earlier)</p><p>UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise (Version 5.0.17 and earlier)</p><p>UniFi OS Server (Version 5.0.6 and earlier)</p><p>UNVR-G2 and UNVR-G2-Pro (Version 5.1.11 and earlier)</p><p>UDM-Beast, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 (Version 5.1.8 and earlier)</p><p><br></p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update your UCG-Industrial to Version 5.1.12 or later.</p><p>Update your UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber to Version 5.1.12 or later.</p><p>Update your UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise to Version 5.1.12 or later.</p><p>Update your UniFi OS Server to Version 5.0.8 or later.</p><p>Update your UNVR-G2 and UNVR-G2-Pro to Version 5.1.12 or later.</p><p>Update your UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 to Version 5.1.10 or later.</p><p>Update your UDM-Beast 5.1.11 or later.</p><p><br></p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>10.0 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE: </strong><a href="https://www.cve.org/CVERecord?id=CVE-2026-34910" rel="noopener noreferrer" target="_blank">CVE-2026-34910</a> (John Carroll)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 5 of 5</strong></p><p>&nbsp;</p><p>A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UCG-Industrial (Version 5.0.13 and earlier)</p><p>UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber (Version 5.0.16 and earlier)</p><p>UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise (Version 5.0.17 and earlier)</p><p>UniFi OS Server (Version 5.0.6 and earlier)</p><p>UNVR-G2 and UNVR-G2-Pro (Version 5.1.11 and earlier)</p><p>UDM-Beast, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 (Version 5.1.8 and earlier)</p><p><br></p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update your UCG-Industrial to Version 5.1.12 or later.</p><p>Update your UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber to Version 5.1.12 or later.</p><p>Update your UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise to Version 5.1.12 or later.</p><p>Update your UniFi OS Server to Version 5.0.8 or later.</p><p>Update your UNVR-G2 and UNVR-G2-Pro to Version 5.1.12 or later.</p><p>Update your UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 to Version 5.1.10 or later.</p><p>Update your UDM-Beast 5.1.11 or later.</p><p><br></p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>7.7 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" rel="noopener noreferrer" target="_blank"> CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N</a></p><p><strong>CVE: </strong><a href="https://www.cve.org/CVERecord?id=CVE-2026-34911" rel="noopener noreferrer" target="_blank">CVE-2026-34911</a> (Hakai Security)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Reference Links:</strong></p><p><a href="https://community.ui.com/releases/UniFi-OS-Server-5-0-8/6b00e638-d383-4767-b886-fde29f5e331b" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Server-5-0-8/6b00e638-d383-4767-b886-fde29f5e331b</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Cloud-Gateways-5-1-12/41549e59-0a2f-4ee9-8450-dee7ec15a58d" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Cloud-Gateways-5-1-12/41549e59-0a2f-4ee9-8450-dee7ec15a58d</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Dream-Routers-5-1-12/4f165cc3-22ab-4144-916d-3c4da7afee3b" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Dream-Routers-5-1-12/4f165cc3-22ab-4144-916d-3c4da7afee3b</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Express-7-5-1-12/abe29aaa-2851-4247-9a92-076a4a467841" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Express-7-5-1-12/abe29aaa-2851-4247-9a92-076a4a467841</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Network-Attached-Storage-5-1-10/6a999e8b-0985-403b-b865-8f3ad63eb60e" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Network-Attached-Storage-5-1-10/6a999e8b-0985-403b-b865-8f3ad63eb60e</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Enterprise-Network-Video-Recorders-5-1-12/e01ca704-079d-40ec-81d0-a36ecfa1f277" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Enterprise-Network-Video-Recorders-5-1-12/e01ca704-079d-40ec-81d0-a36ecfa1f277</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Network-Video-Recorders-5-1-12/c3b995a8-3bea-4830-a265-50f077ed9f7f" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Network-Video-Recorders-5-1-12/c3b995a8-3bea-4830-a265-50f077ed9f7f</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Cloud-Keys-5-1-12/b8c2c586-be95-44e1-921c-26201f1838ea" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Cloud-Keys-5-1-12/b8c2c586-be95-44e1-921c-26201f1838ea</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Enterprise-Fortress-Gateway-5-1-12/9427e825-b0c9-487d-b2a9-5cbb393f219a" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Enterprise-Fortress-Gateway-5-1-12/9427e825-b0c9-487d-b2a9-5cbb393f219a</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Dream-Machines-5-1-12/6a229a80-ed47-4509-a9a3-046122ecc1b9" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Dream-Machines-5-1-12/6a229a80-ed47-4509-a9a3-046122ecc1b9</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Dream-Machine-Beast-5-1-11/12eae3e2-94b5-4efe-81d8-e5881721fb22" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Dream-Machine-Beast-5-1-11/12eae3e2-94b5-4efe-81d8-e5881721fb22</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Dream-Wall-5-1-12/e2fc2a8c-7546-4e7a-b545-5cabb1f5570f" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Dream-Wall-5-1-12/e2fc2a8c-7546-4e7a-b545-5cabb1f5570f</a></p><p><a href="https://community.ui.com/releases/UniFi-OS-Express-4-0-14/f0b5dbcf-c3b9-4daa-8034-14d0900d07bd" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Express-4-0-14/f0b5dbcf-c3b9-4daa-8034-14d0900d07bd</a></p>]]></description>
            <link>https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b</link>
            <guid isPermaLink="false">84811c09-4cf4-42ab-bd61-cc994445963b</guid>
            <category><![CDATA[unifi-gateway-cloudkey]]></category>
            <category><![CDATA[security]]></category>
            <dc:creator><![CDATA[UI-Marcus]]></dc:creator>
            <pubDate>Thu, 21 May 2026 20:46:22 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Security Advisory Bulletin 063]]></title>
            <description><![CDATA[<h2>Overview</h2><p>Published: April 07, 2026</p><p>Version: 1.0</p><p>Revision: 1.0</p><p><strong>&nbsp;</strong></p><p><strong>&nbsp;</strong></p><p><strong>Summary 1 of 5</strong></p><p><br></p><p>A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on the system that could be used for a remote code execution (RCE).</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UniFi Play PowerAmp (Version 1.0.35 and earlier)</p><p>UniFi Play Audio Port&nbsp;(Version 1.0.24 and earlier)</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update UniFi Play PowerAmp to Version 1.0.38 or later</p><p>Update UniFi Play Audio Port&nbsp;to Version 1.1.9 or later</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.8 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></p><p><strong>CVE: </strong><a href="https://www.cve.org/CVERecord?id=CVE-2026-22562" rel="noopener noreferrer" target="_blank">CVE-2026-22562</a> (Bongeun Koo (@kiddo_pwn))</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 2 of 5</strong></p><p>A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access to the UniFi Play network.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UniFi Play PowerAmp (Version 1.0.35 and earlier)</p><p>UniFi Play Audio Port&nbsp;(Version 1.0.24 and earlier)</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update UniFi Play PowerAmp to Version 1.0.38 or later</p><p>Update UniFi Play Audio Port&nbsp;to Version 1.1.9 or later</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.8 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></p><p><strong>CVE: </strong><a href="https://www.cve.org/CVERecord?id=CVE-2026-22563" rel="noopener noreferrer" target="_blank">CVE-2026-22563</a> (Bongeun Koo (@kiddo_pwn))</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 3 of 5</strong></p><p><br></p><p>An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthorized changes to the system.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Play PowerAmp (Version 1.0.35 and earlier)</p><p>UniFi Play Audio Port&nbsp;(Version 1.0.24 and earlier)</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update UniFi Play PowerAmp to Version 1.0.38 or later</p><p>Update UniFi Play Audio Port&nbsp;to Version 1.1.9 or later</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.8 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></p><p><strong>CVE: </strong><a href="https://www.cve.org/CVERecord?id=CVE-2026-22564" rel="noopener noreferrer" target="_blank">CVE-2026-22564</a> (Bongeun Koo (@kiddo_pwn))</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 4 of 5</strong></p><p>An Improper Input Validation vulnerability could allow a malicious actor with access to the UniFi Play network to cause the device to stop responding.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Play PowerAmp (Version 1.0.35 and earlier)</p><p>UniFi Play Audio Port&nbsp;(Version 1.0.24 and earlier)</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update UniFi Play PowerAmp to Version 1.0.38 or later</p><p>Update UniFi Play Audio Port&nbsp;to Version 1.1.9 or later</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>7.5 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></p><p><strong>CVE: </strong><a href="https://www.cve.org/CVERecord?id=CVE-2026-22565" rel="noopener noreferrer" target="_blank">CVE-2026-22565</a> (Bongeun Koo (@kiddo_pwn))</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 5 of 5</strong></p><p>An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain UniFi Play WiFi credentials.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Play PowerAmp (Version 1.0.35 and earlier)</p><p>UniFi Play Audio Port&nbsp;(Version 1.0.24 and earlier)</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update UniFi Play PowerAmp to Version 1.0.38 or later</p><p>Update UniFi Play Audio Port&nbsp;to Version 1.1.9 or later</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>7.5 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></p><p><strong>CVE: </strong><a href="https://www.cve.org/CVERecord?id=CVE-2026-22566" rel="noopener noreferrer" target="_blank">CVE-2026-22566</a> (Bongeun Koo (@kiddo_pwn))</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Reference Links:</strong></p><p><a href="https://community.ui.com/releases/UniFi-Play-PowerAmp-1-0-38/6f17da40-f0d2-4a7e-89e3-2133b89ff5a7" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Play-PowerAmp-1-0-38/6f17da40-f0d2-4a7e-89e3-2133b89ff5a7</a></p><p><a href="https://community.ui.com/releases/UniFi-Play-Audio-Port-1-1-9/2e270ee4-9a7e-4307-967a-f9cd900bef83" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Play-Audio-Port-1-1-9/2e270ee4-9a7e-4307-967a-f9cd900bef83</a></p>]]></description>
            <link>https://community.ui.com/releases/Security-Advisory-Bulletin-063-063/e468dd4b-5090-4ef8-89d8-939903c08e83</link>
            <guid isPermaLink="false">e468dd4b-5090-4ef8-89d8-939903c08e83</guid>
            <category><![CDATA[unifi-play]]></category>
            <category><![CDATA[security]]></category>
            <dc:creator><![CDATA[UI-Marcus]]></dc:creator>
            <pubDate>Tue, 07 Apr 2026 15:16:14 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Security Advisory Bulletin 062]]></title>
            <description><![CDATA[<h2>Overview</h2><p><strong>Published: March 18, 2026</strong></p><p><strong>Updated: March 21,2026</strong></p><p><strong>Version: 1.1</strong></p><p><strong>Revision: 1.1</strong></p><p><strong>&nbsp;</strong></p><p><strong>Summary 1 of 3</strong></p><p>&nbsp;</p><p><br></p><p>A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account.&nbsp;</p><p>&nbsp;</p><p><br></p><p><strong>Affected Products:</strong></p><p>Official Release: UniFi Network application (Version 10.1.85 and earlier)</p><p>Release Candidate: UniFi Network application (Version 10.2.93 and earlier)</p><p>UniFi Express (UX): UniFi Network application (Version 9.0.114 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Official Release: Update UniFi Network application to Version 10.1.89 or later.</p><p>Release Candidate: Update UniFi Network application to Version 10.2.97 or later.</p><p>UniFi Express (UX): Update UniFi Express firmware to 4.0.13 or later, which updates the UniFi Network application to Version 9.0.118 or later.</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.1 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>10.0 (Critical)</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE:&nbsp;</strong><a href="https://www.cve.org/CVERecord?id=CVE-2026-22557" rel="noopener noreferrer" target="_blank">CVE-2026-22557</a> (n00r3(@izn0u))</p><p>&nbsp;</p><p><br></p><p><strong>Summary 2 of 3</strong></p><p>&nbsp;</p><p><br></p><p>An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to escalate privileges.</p><p>&nbsp;</p><p><br></p><p><strong>Affected Products:</strong></p><p>Official Release: UniFi Network application (Version 10.1.85 and earlier)</p><p>Release Candidate: UniFi Network application (Version 10.2.93 and earlier)</p><p>UniFi Express (UX): UniFi Network application (Version 9.0.114 and earlier)&nbsp;</p><p><strong>&nbsp;</strong></p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Official Release: Update UniFi Network application to Version 10.1.89 or later.</p><p>Release Candidate: Update UniFi Network application to Version 10.2.97 or later.</p><p>UniFi Express (UX): Update UniFi Express firmware to 4.0.13 or later, which updates the UniFi Network application to Version 9.0.118 or later.</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.1 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>7.7 (High)</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N</a></p><p><strong>CVE:&nbsp;</strong><a href="https://www.cve.org/CVERecord?id=CVE-2026-22558" rel="noopener noreferrer" target="_blank">CVE-2026-22558</a> (Garett Kopcha (@0x5t))</p><p>&nbsp;</p><p>&nbsp;</p><p><br></p><p><strong>Summary 3 of 3</strong></p><p>&nbsp;</p><p><br></p><p>An Improper Input Validation vulnerability in UniFi Network Server may allow unauthorized access to an account if the account owner is socially engineered into clicking a malicious link.</p><p>&nbsp;</p><p><br></p><p><strong>Affected Products:</strong></p><p>UniFi Network Server (Version 10.1.85 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update UniFi Network Server to Version 10.1.89 or later.</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.1 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>8.8 (High)</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS: </strong><a href="https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></p><p><strong>CVE:&nbsp;</strong><a href="https://www.cve.org/CVERecord?id=CVE-2026-22559" rel="noopener noreferrer" target="_blank">CVE-2026-22559</a><strong> </strong>(Shubham Gupta (@hackerspider1))</p><p>&nbsp;</p><p>&nbsp;</p><p><br></p><p><strong>Reference Links:</strong></p><p><a href="https://community.ui.com/releases/UniFi-OS-Express-4-0-13/27e4730e-5fb7-4303-9c0f-d2f572d861c2" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-OS-Express-4-0-13/27e4730e-5fb7-4303-9c0f-d2f572d861c2</a></p><p><a href="https://community.ui.com/releases/UniFi-Network-Application-10-2-97/7c599511-d03a-4dce-8832-93b90cbaa41d" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Network-Application-10-2-97/7c599511-d03a-4dce-8832-93b90cbaa41d</a></p><p><a href="https://community.ui.com/releases/UniFi-Network-Application-10-1-89/625f366f-7ea5-4266-bd9f-500180494035" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Network-Application-10-1-89/625f366f-7ea5-4266-bd9f-500180494035</a></p><p><a href="https://community.ui.com/releases/UniFi-Network-Application-9-0-118/72fa9862-3c4f-4e9b-a028-4fc7a0b2ba28" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Network-Application-9-0-118/72fa9862-3c4f-4e9b-a028-4fc7a0b2ba28</a></p>]]></description>
            <link>https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b</link>
            <guid isPermaLink="false">c29719c0-405e-4d4a-8f26-e343e99f931b</guid>
            <category><![CDATA[security]]></category>
            <category><![CDATA[unifi-network]]></category>
            <dc:creator><![CDATA[UI-Marcus]]></dc:creator>
            <pubDate>Wed, 18 Mar 2026 20:17:00 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Security Advisory Bulletin 061]]></title>
            <description><![CDATA[<h2>Overview</h2><p>Published: January 06, 2026</p><p>Version: 1.0</p><p>Revision: 1.0</p><p>&nbsp;</p><p>A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>airMAX AC (Version 8.7.20 and earlier)</p><p>airMAX M&nbsp;(Version 6.3.22 and earlier)</p><p>airFiber AF60-XG&nbsp;(Version 1.2.2 and earlier)</p><p>airFiber AF60&nbsp;(Version 2.6.7 and earlier)</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update your airMAX AC to Version 8.7.21 or later.</p><p>Update your airMAX M&nbsp;to Version 6.3.24 or later.</p><p>Update your airFiber AF60-XG to Version 1.2.3 or later.</p><p>Update your airFiber AF60 to Version 2.6.8 or later.</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.1 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>8.8 (High)</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></p><p><strong>CVE:&nbsp;</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21639" rel="noopener noreferrer" target="_blank">CVE-2026-21639</a> (Gaston Aznarez, Principal Security Researcher at Faraday)</p><p>&nbsp;</p><p><strong>Reference Links:</strong></p><p><a href="https://community.ui.com/releases/airMAX-AC-8-7-21/804eb7e2-1790-4143-8e98-2e8c0e29463e" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/airMAX-AC-8-7-21/804eb7e2-1790-4143-8e98-2e8c0e29463e</a></p><p><a href="https://community.ui.com/releases/airMAX-M-6-3-24/e190e518-36dd-4430-9a1d-73a5866121b3" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/airMAX-M-6-3-24/e190e518-36dd-4430-9a1d-73a5866121b3</a></p><p><a href="https://community.ui.com/releases/AF60-HD-XG-1-2-3/d376023a-4698-47eb-9c70-4b2d5e8f4c41" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/AF60-HD-XG-1-2-3/d376023a-4698-47eb-9c70-4b2d5e8f4c41</a></p><p><a href="https://community.ui.com/releases/AF60-AF60-LR-2-6-8/701398a3-858f-455c-9b84-9c964343a533" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/AF60-AF60-LR-2-6-8/701398a3-858f-455c-9b84-9c964343a533</a></p>]]></description>
            <link>https://community.ui.com/releases/Security-Advisory-Bulletin-061-061/1e4fe5f8-29c7-4a7d-a518-01b1537983ba</link>
            <guid isPermaLink="false">1e4fe5f8-29c7-4a7d-a518-01b1537983ba</guid>
            <category><![CDATA[security]]></category>
            <category><![CDATA[airmax]]></category>
            <category><![CDATA[airfiber]]></category>
            <category><![CDATA[60GHz]]></category>
            <dc:creator><![CDATA[UI-Marcus]]></dc:creator>
            <pubDate>Tue, 06 Jan 2026 18:58:15 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Security Advisory Bulletin 060]]></title>
            <description><![CDATA[<h2>Overview</h2><p>Published: January 06, 2026</p><p>Version: 1.0</p><p>Revision: 1.0</p><p>&nbsp;</p><p>A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UBB-XG (Version 1.2.2 and earlier)</p><p>UDB-Pro/UDB-Pro-Sector&nbsp;(Version 1.4.1 and earlier)</p><p>UBB&nbsp;(Version 3.1.5 and earlier)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update your UBB-XG to Version 1.2.3 or later.</p><p>Update your UDB-Pro/UDB-Pro-Sector&nbsp;to Version 1.4.2 or later.</p><p>Update your UBB to Version 3.1.7 or later.</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.1 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>8.8 (High)</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></p><p><strong>CVE:&nbsp;</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21638" rel="noopener noreferrer" target="_blank">CVE-2026-21638</a> (Gaston Aznarez, Principal Security Researcher at Faraday)</p><p>&nbsp;</p><p><br></p><p><strong>Reference Links:</strong></p><p><a href="https://community.ui.com/releases/UniFi-Building-Bridge-XG-1-2-3/c1eede93-ed3a-47e1-b912-2a8ab46b9cfa" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Building-Bridge-XG-1-2-3/c1eede93-ed3a-47e1-b912-2a8ab46b9cfa</a></p><p><a href="https://community.ui.com/releases/UniFi-Device-Bridge-Pro-Sector-1-4-2/59fb6e3a-5b8e-4645-b841-41df2edca2c9" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Device-Bridge-Pro-Sector-1-4-2/59fb6e3a-5b8e-4645-b841-41df2edca2c9</a></p><p><a href="https://community.ui.com/releases/UniFi-Building-Bridge-3-1-7/6fd38113-df70-4e13-9b26-678371b71c72" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Building-Bridge-3-1-7/6fd38113-df70-4e13-9b26-678371b71c72</a></p>]]></description>
            <link>https://community.ui.com/releases/Security-Advisory-Bulletin-060-060/cde18da7-2bc4-41bb-a9cc-48a4a4c479c1</link>
            <guid isPermaLink="false">cde18da7-2bc4-41bb-a9cc-48a4a4c479c1</guid>
            <category><![CDATA[unifi-wireless]]></category>
            <category><![CDATA[security]]></category>
            <dc:creator><![CDATA[UI-Marcus]]></dc:creator>
            <pubDate>Tue, 06 Jan 2026 18:58:06 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Security Advisory Bulletin 059]]></title>
            <description><![CDATA[<h2>Overview</h2><p><br></p><p>Published: January 5, 2025</p><p>Version: 1.0</p><p>Revision: 1.0</p><p>An Improper Access Control could allow a malicious actor in Wi-Fi range to the EV Station Lite (v1.5.2 and earlier) to use WiFi AutoLink feature on a device that was only adopted via Ethernet.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UniFi Connect EV Station Lite (Version 1.5.2 and earlier)</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update UniFi Connect EV Station Lite to Version 1.6.1 or later.&nbsp;</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.1 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>5.3 (Medium)</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</a></p><p><strong>CVE:&nbsp;</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21635" rel="noopener noreferrer" target="_blank">CVE-2026-21635</a> (Bongeun Koo (@kiddo_pwn))</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Reference Links:</strong></p><p><a href="https://community.ui.com/releases/UniFi-Connect-EV-Station-Lite-1-6-1/812cb388-7806-4638-9f1a-39ae4bf5f93f" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Connect-EV-Station-Lite-1-6-1/812cb388-7806-4638-9f1a-39ae4bf5f93f</a></p>]]></description>
            <link>https://community.ui.com/releases/Security-Advisory-Bulletin-059-059/0c0b7f7a-68b7-41b9-987e-554f4b40e0e6</link>
            <guid isPermaLink="false">0c0b7f7a-68b7-41b9-987e-554f4b40e0e6</guid>
            <category><![CDATA[unifi-connect]]></category>
            <category><![CDATA[security]]></category>
            <dc:creator><![CDATA[UI-Marcus]]></dc:creator>
            <pubDate>Mon, 05 Jan 2026 15:37:00 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Security Advisory Bulletin 058]]></title>
            <description><![CDATA[<h2>Overview</h2><p>Published: January 5, 2026</p><p>Version: 1.0</p><p>Revision: 1.0</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 1 of 2</strong></p><p>&nbsp;</p><p>A malicious actor with access to the adjacent network could obtain unauthorized access to a UniFi Protect Camera by exploiting a discovery protocol vulnerability in the Unifi Protect Application (Version 6.1.79 and earlier).</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Protect Application (Version 6.1.79 and earlier).</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update your UniFi Protect Application to Version 6.2.72 or later.</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.1 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>8.8 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></p><p><strong>CVE: </strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21633" rel="noopener noreferrer" target="_blank">CVE-2026-21633</a> (David BERARD from @Synacktiv working with Trend Micro Zero Day Initiative)</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Summary 2 of 2</strong></p><p>&nbsp;</p><p>A malicious actor with access to the adjacent network could overflow the UniFi Protect Application (Version 6.1.79 and earlier) discovery protocol causing it to restart.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Protect Application (Version 6.1.79 and earlier).</p><p>&nbsp;&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update your UniFi Protect Application to Version 6.2.72 or later.</p><p>&nbsp;&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.1 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>6.5 Medium</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></p><p><strong>CVE:&nbsp;</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21634" rel="noopener noreferrer" target="_blank">CVE-2026-21634</a> (David BERARD from @Synacktiv working with Trend Micro Zero Day Initiative)</p><p>&nbsp;</p><p>&nbsp;</p><p>&nbsp;</p><p><strong>Reference Links:</strong></p><p><a href="https://community.ui.com/releases/UniFi-Protect-Application-6-2-72/b45268b0-bee2-41c7-b409-8e2d5c0ca47c" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Protect-Application-6-2-72/b45268b0-bee2-41c7-b409-8e2d5c0ca47c</a></p>]]></description>
            <link>https://community.ui.com/releases/Security-Advisory-Bulletin-058-058/6922ff20-8cd7-4724-8d8c-676458a2d0f9</link>
            <guid isPermaLink="false">6922ff20-8cd7-4724-8d8c-676458a2d0f9</guid>
            <category><![CDATA[unifi-protect]]></category>
            <category><![CDATA[security]]></category>
            <dc:creator><![CDATA[UI-Marcus]]></dc:creator>
            <pubDate>Mon, 05 Jan 2026 15:06:03 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Security Advisory Bulletin 057]]></title>
            <description><![CDATA[<h2>Overview</h2><p>Published: December 16, 2025</p><p>Version: 1.0</p><p>Revision: 1.0</p><p><strong>&nbsp;</strong></p><p>A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page.&nbsp;</p><p>This plugin is disabled by default.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UCRM Argentina AFIP invoices Plugin (Version 1.2.0 and earlier)</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update&nbsp;UCRM Argentina AFIP invoices Plugin&nbsp;to Version 1.3.0&nbsp;or later.</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>7.5 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS: </strong><a href="https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</a></p><p><strong>CVE: </strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59467" rel="noopener noreferrer" target="_blank">CVE-2025-59467</a>&nbsp;(Rishabh Jain (RJCyber) of cyberplanet)</p>]]></description>
            <link>https://community.ui.com/releases/Security-Advisory-Bulletin-057-057/6d3f2a51-22b8-47a1-9296-1e9dcd64e073</link>
            <guid isPermaLink="false">6d3f2a51-22b8-47a1-9296-1e9dcd64e073</guid>
            <category><![CDATA[security]]></category>
            <category><![CDATA[uisp-app]]></category>
            <dc:creator><![CDATA[UI-Marcus]]></dc:creator>
            <pubDate>Tue, 16 Dec 2025 16:42:28 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Security Advisory Bulletin 056]]></title>
            <description><![CDATA[<h2>Overview</h2><p>Published: October 23, 2025</p><p>Version: 1.0</p><p>Revision: 1.0</p><p><strong>&nbsp;</strong>&nbsp;</p><p>A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.&nbsp;</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Access Application (Version 3.3.22 through 3.4.31).</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update your UniFi Access Application to Version 4.0.21 or later.</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>10.0 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE: </strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-52665" rel="noopener noreferrer" target="_blank">CVE-2025-52665</a> (Catchify Security (@catchifySA))</p><p>&nbsp;</p><p><strong>Reference Links:</strong></p><p><a href="https://community.ui.com/releases/UniFi-Access-Application-4-0-21/f3b63db6-6e51-442e-b5a6-24b67fe82f44" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Access-Application-4-0-21/f3b63db6-6e51-442e-b5a6-24b67fe82f44</a></p>]]></description>
            <link>https://community.ui.com/releases/Security-Advisory-Bulletin-056-056/ce97352d-91cd-40a7-a2f4-2c73b3b30191</link>
            <guid isPermaLink="false">ce97352d-91cd-40a7-a2f4-2c73b3b30191</guid>
            <category><![CDATA[unifi-access]]></category>
            <category><![CDATA[security]]></category>
            <dc:creator><![CDATA[UI-Marcus]]></dc:creator>
            <pubDate>Thu, 23 Oct 2025 14:03:17 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Security Advisory Bulletin 055]]></title>
            <description><![CDATA[<h2>Overview</h2><p>Published: October 15, 2025</p><p>Version: 1.0</p><p>Revision: 1.0</p><p><br></p><p><strong>&nbsp;</strong></p><p>A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This issue could allow an attacker with access to the UniFi Talk management network to execute internal debug operations through the device API.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Talk Touch (Version 1.21.16 and earlier)</p><p>UniFi Talk Touch Max (Version 2.21.22 and earlier)</p><p>UniFi Talk G3 Phones (Version 3.21.26 and earlier)</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update the UniFi Talk Touch to Version 1.21.17 or later.</p><p>Update the UniFi Talk Touch Max to Version 2.21.23 or later.</p><p>Update the UniFi Talk G3 Phones to Version 3.21.27 or later.</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>7.3 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" rel="noopener noreferrer" target="_blank">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a></p><p><strong>CVE: </strong><a href="https://www.cve.org/CVERecord?id=CVE-2025-52663" rel="noopener noreferrer" target="_blank">CVE-2025-52663</a> (Junhyung Cho (@da2rim) &amp; Bongeun Koo (@kiddo_pwn))</p><p>&nbsp;</p><p><strong>Reference Links:</strong></p><p><a href="https://community.ui.com/releases/UTP-Touch-1-21-17/d38229dd-7940-4dd8-a888-d5c902cfe961" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UTP-Touch-1-21-17/d38229dd-7940-4dd8-a888-d5c902cfe961</a></p><p><a href="https://community.ui.com/releases/UTP-Touch-Max-2-21-23/7e92e95a-a2f7-4f31-88d8-04c98c0da282" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UTP-Touch-Max-2-21-23/7e92e95a-a2f7-4f31-88d8-04c98c0da282</a></p><p><a href="https://community.ui.com/releases/UniFi-Talk-G3-Phones-3-21-27/f7c84184-9d09-4ef4-960b-a2717a68e780" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Talk-G3-Phones-3-21-27/f7c84184-9d09-4ef4-960b-a2717a68e780</a></p>]]></description>
            <link>https://community.ui.com/releases/Security-Advisory-Bulletin-055-055/9b65527b-489c-4f16-ac34-2b887754db1e</link>
            <guid isPermaLink="false">9b65527b-489c-4f16-ac34-2b887754db1e</guid>
            <category><![CDATA[unifi-talk]]></category>
            <category><![CDATA[security]]></category>
            <dc:creator><![CDATA[UI-Marcus]]></dc:creator>
            <pubDate>Wed, 15 Oct 2025 15:37:53 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Security Advisory Bulletin 054]]></title>
            <description><![CDATA[<h2>Overview</h2><p>Published: Aug 13, 2025</p><p>Version: 1.0</p><p>Revision: 1.0</p><p><strong>&nbsp;</strong></p><p>An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.11.0 and earlier) could allow a Command Injection by a malicious actor with access to EdgeSwitch adjacent network.</p><p>&nbsp;&nbsp;</p><p><strong>Affected Products:</strong></p><p>EdgeMAX EdgeSwitch (Version 1.11.0 and earlier)&nbsp;</p><p>&nbsp;&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update the EdgeMAX EdgeSwitch to <strong>Version 1.11.1 or later</strong>.</p><p>&nbsp;&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>7.5 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a></p><p><strong>CVE: </strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-48978" rel="noopener noreferrer" target="_blank">CVE-2025-48978</a> (Jeff Barbi)</p><p>&nbsp;</p><p><strong>Reference Links:</strong></p><p><a href="https://community.ui.com/releases/EdgeMAX-EdgeSwitch-1-11-1/ffb7c3ab-94c5-4c98-bd55-d9fc93769c77" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/EdgeMAX-EdgeSwitch-1-11-1/ffb7c3ab-94c5-4c98-bd55-d9fc93769c77</a></p>]]></description>
            <link>https://community.ui.com/releases/Security-Advisory-Bulletin-054-054/3033f0b7-aca6-4d70-8c51-d3e706bd0ca7</link>
            <guid isPermaLink="false">3033f0b7-aca6-4d70-8c51-d3e706bd0ca7</guid>
            <category><![CDATA[security]]></category>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[UI-Marcus]]></dc:creator>
            <pubDate>Wed, 13 Aug 2025 22:54:03 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Security Advisory Bulletin 053]]></title>
            <description><![CDATA[<h2>Overview</h2><p>Published: Aug 07, 2025</p><p>Updated:&nbsp;Aug 18, 2025</p><p>Version: 1.2</p><p>Revision: 1.2</p><p><strong>&nbsp;</strong></p><p><strong>Summary 1 of 3</strong></p><p>&nbsp;</p><p>&nbsp;</p><p>Multiple Incorrect Permission Assignment for Critical Resource in UISP Application may allow a malicious actor with certain permissions to escalate privileges.&nbsp;</p><p><strong>&nbsp;</strong></p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UISP Application (Version 2.4.211 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update UISP Application to Version 2.4.220 or later</p><p><strong>&nbsp;</strong></p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>8.1 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H</a></p><p><strong>CVE: </strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-27216" rel="noopener noreferrer" target="_blank">CVE-2025-27216</a> (abdulsec @moodiAbdoul and n00r3 @izn0u)</p><p><strong>&nbsp;</strong></p><p><strong>&nbsp;</strong></p><p><strong>Summary 2 of 3</strong></p><p>&nbsp;</p><p>A Server-Side Request Forgery (SSRF) in the UISP Application may allow a malicious actor with certain permissions to make requests outside of UISP Application scope.</p><p><strong>&nbsp;</strong></p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UISP Application (Version 2.4.211 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update UISP Application to Version 2.4.220 or later</p><p><strong>&nbsp;</strong></p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>6.3 Medium</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" rel="noopener noreferrer" target="_blank">CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N</a></p><p><strong>CVE:</strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22957" rel="noopener noreferrer" target="_blank"><strong> </strong></a><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-27217" rel="noopener noreferrer" target="_blank">CVE-2025-27217</a><strong> </strong>(Michael Price, Rishabh Jain and Muhammad Ali of cyberplanet)<strong> </strong></p><p><strong>&nbsp;</strong></p><p><strong>Summary 3 of 3</strong></p><p><strong>&nbsp;</strong></p><p>An Improper Input Validation in UISP Application could allow a Command Injection by a malicious actor with High Privileges and local access.</p><p><strong>&nbsp;</strong></p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p><strong>UISP Application (Version 2.4.211 and earlier)</strong></p><p><strong>&nbsp;</strong></p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p><strong>Update UISP Application to Version 2.4.220 or later</strong></p><p><strong>&nbsp;</strong></p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: 8.2</strong> High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</a></p><p><strong>CVE: </strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-48979" rel="noopener noreferrer" target="_blank">CVE-2025-48979</a> ( wa1tal0ne )<strong>&nbsp;</strong></p><p><br></p><p><strong> </strong></p><p><strong> </strong></p><p><strong>Reference Links:</strong></p><p><a href="https://community.ui.com/releases/UISP-Application-2-4-220/b428b276-c4a6-4b90-b97b-1860ff2bb46d" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UISP-Application-2-4-220/b428b276-c4a6-4b90-b97b-1860ff2bb46d</a></p>]]></description>
            <link>https://community.ui.com/releases/Security-Advisory-Bulletin-053-053/b0c4aa38-90aa-412d-b5b9-6395e057d822</link>
            <guid isPermaLink="false">b0c4aa38-90aa-412d-b5b9-6395e057d822</guid>
            <category><![CDATA[security]]></category>
            <category><![CDATA[uisp-app]]></category>
            <dc:creator><![CDATA[UI-Marcus]]></dc:creator>
            <pubDate>Thu, 07 Aug 2025 14:39:33 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Security Advisory Bulletin 052]]></title>
            <description><![CDATA[<h2>Overview</h2><p>Published: Aug 06, 2025</p><p>Version: 1.0</p><p>Revision: 1.0</p><p><strong>&nbsp;</strong></p><p><strong>Summary 1 of 4</strong></p><p><strong>&nbsp;</strong></p><p>Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a Command Injection by a malicious actor with network access to the UniFi Connect EV Station Lite.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UniFi Connect EV Station Lite (Version 1.5.1 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update UniFi Connect EV Station Lite to Version 1.5.2 or later</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.8 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></p><p><strong>CVE:</strong> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-24285" rel="noopener noreferrer" target="_blank">CVE-2025-24285</a> (Bongeun Koo (@kiddo_pwn)</p><p><br></p><p><strong>&nbsp;</strong></p><p><strong>&nbsp;</strong></p><p><strong>Summary 2 of 4</strong></p><p>&nbsp;</p><p>An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect devices to enable Android Debug Bridge (ADB) and make unsupported changes to the system.</p><p>&nbsp;</p><p>Affected Products:</p><p>UniFi Connect EV Station Pro (Version 1.5.18 and earlier)</p><p>UniFi Connect Display (Version 1.9.324 and earlier)</p><p>UniFi Connect Display Cast (Version 1.9.301 and earlier)</p><p>UniFi Connect Display Cast Pro (Version 1.0.78 and earlier)</p><p>UniFi Connect Display Cast Lite (Version 1.0.3 and earlier)</p><p><br></p><p><strong>Mitigation:</strong></p><p>Update UniFi Connect EV Station Pro to Version 1.5.27 or later</p><p>Update UniFi Connect Display to Version 1.13.6 or later</p><p>Update UniFi Connect Display Cast to Version 1.10.3 or later</p><p>Update UniFi Connect Display Cast Pro to Version 1.0.83 or later</p><p>Update UniFi Connect Display Cast Lite to Version 1.1.3 or later</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>4.9 Medium</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" rel="noopener noreferrer" target="_blank">CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N</a></p><p><strong>CVE: </strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-27213" rel="noopener noreferrer" target="_blank">CVE-2025-27213</a> (Bongeun Koo (@kiddo_pwn and Sina Kheirkhah (@SinSinology) at Zero Day Initiative - Pwn2Own Automotive 2025 Tokyo)</p><p><strong>&nbsp;</strong></p><p><strong>&nbsp;</strong></p><p><strong>&nbsp;</strong></p><p><strong>Summary 3 of 4</strong></p><p>&nbsp;</p><p>&nbsp;</p><p>A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious actor with physical or adjacent access to perform an unauthorized factory reset.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UniFi Connect EV Station Pro (Version 1.5.18 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update UniFi Connect EV Station Pro to Version 1.5.27 or later</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>6.5 Medium</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" rel="noopener noreferrer" target="_blank">CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a></p><p><strong>CVE: </strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-27214" rel="noopener noreferrer" target="_blank">CVE-2025-27214</a> (Bongeun Koo (@kiddo_pwn and Sina Kheirkhah (@SinSinology) at Zero Day Initiative - Pwn2Own Automotive 2025 Tokyo)</p><p><br></p><p><br></p><p><strong>&nbsp;</strong></p><p><strong>&nbsp;</strong></p><p><strong>Summary 4 of 4</strong></p><p>&nbsp;</p><p>An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect Display Cast devices to make unsupported changes to the system.</p><p><strong>&nbsp;</strong></p><p><strong>Affected Products:</strong></p><p>UniFi Connect Display Cast (Version 1.10.3 and earlier)</p><p>UniFi Connect Display Cast Pro (Version 1.0.89 and earlier)</p><p>UniFi Connect Display Cast Lite (Version 1.0.3 and earlier)</p><p><strong>&nbsp;</strong></p><p><strong>Mitigation:</strong></p><p>Update UniFi Connect Display Cast to Version 1.10.7 or later</p><p>Update UniFi Connect Display Cast Pro to Version 1.0.94 or later</p><p>Update UniFi Connect Display Cast Lite to Version 1.1.8 or later</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>2.7 Low</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" rel="noopener noreferrer" target="_blank">CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N</a></p><p><strong>CVE: </strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-27215" rel="noopener noreferrer" target="_blank">CVE-2025-27215</a> (Bongeun Koo (@kiddo_pwn) &amp; Junhyung Cho (@da2rim))</p><p><strong>&nbsp;</strong></p><p><strong>&nbsp;</strong></p><p><strong>&nbsp;</strong></p><p><strong>Reference Links:</strong></p><p><br></p><p><a href="https://community.ui.com/releases/UniFi-Connect-EV-Station-Lite-1-5-2/7c98114e-8e8f-43a0-b741-f64d5d6ca0b2" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Connect-EV-Station-Lite-1-5-2/7c98114e-8e8f-43a0-b741-f64d5d6ca0b2</a></p><p><a href="https://community.ui.com/releases/UniFi-Connect-EV-Station-Pro-1-5-27/d465b2c9-63f3-4ae2-b387-6ea11460c938" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Connect-EV-Station-Pro-1-5-27/d465b2c9-63f3-4ae2-b387-6ea11460c938</a></p><p><a href="https://community.ui.com/releases/UniFi-Connect-Display-1-13-6/f4a26d7b-0134-4605-b3cc-5384f429e349" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Connect-Display-1-13-6/f4a26d7b-0134-4605-b3cc-5384f429e349</a></p><p><a href="https://community.ui.com/releases/UniFi-Connect-Display-Cast-1-10-7/dbda7a50-e99e-4e31-bc2a-8019436ff081" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Connect-Display-Cast-1-10-7/dbda7a50-e99e-4e31-bc2a-8019436ff081</a></p><p><a href="https://community.ui.com/releases/UniFi-Connect-Display-Cast-Pro-1-0-94/f184a367-1781-49c3-896a-820368022226" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Connect-Display-Cast-Pro-1-0-94/f184a367-1781-49c3-896a-820368022226</a></p><p><a href="https://community.ui.com/releases/UniFi-Connect-Display-Cast-Lite-1-1-8/ca33b370-4aef-4a63-bc75-96e63e30750d" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Connect-Display-Cast-Lite-1-1-8/ca33b370-4aef-4a63-bc75-96e63e30750d</a></p>]]></description>
            <link>https://community.ui.com/releases/Security-Advisory-Bulletin-052-052/ac1251ee-5bb5-4cdf-8a71-68acd1775bb6</link>
            <guid isPermaLink="false">ac1251ee-5bb5-4cdf-8a71-68acd1775bb6</guid>
            <category><![CDATA[unifi-connect]]></category>
            <category><![CDATA[security]]></category>
            <dc:creator><![CDATA[UI-Marcus]]></dc:creator>
            <pubDate>Wed, 06 Aug 2025 17:01:09 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Security Advisory Bulletin 051]]></title>
            <description><![CDATA[<h2>Overview</h2><p>Published: July 16, 2025</p><p>Version: 1.0</p><p>Revision: 1.0</p><p><strong>&nbsp;</strong></p><p>An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access management network.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Access Reader Pro (Version 2.14.21 and earlier)</p><p>UniFi Access G2 Reader Pro (Version 1.10.32 and earlier)</p><p>UniFi Access G3 Reader Pro (Version 1.10.30 and earlier)</p><p>UniFi Access Intercom (Version 1.7.28 and earlier)</p><p>UniFi Access G3 Intercom (Version 1.7.29 and earlier)</p><p>UniFi Access Intercom Viewer (Version 1.3.20 and earlier)</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update UniFi Access Reader Pro to Version 2.15.9 or later</p><p>Update UniFi Access G2 Reader Pro to Version 1.11.23 or later</p><p>Update UniFi Access G3 Reader Pro to Version 1.11.22 or later</p><p>Update UniFi Access Intercom to Version 1.8.22 or later</p><p>Update UniFi Access G3 Intercom to Version 1.8.22 or later</p><p>Update UniFi Access Intercom Viewer to Version 1.4.39 or later</p><p>&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>9.8 Critical</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></p><p><strong>CVE: </strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-27212" rel="noopener noreferrer" target="_blank">CVE-2025-27212</a> (Bongeun Koo (@kiddo_pwn) &amp; Junhyung Cho (@da2Rim))</p><p>&nbsp;</p><p><strong>Reference Links:</strong></p><p><a href="https://community.ui.com/releases/UniFi-Access-Reader-Pro-2-15-9/e77b14b5-226a-4efa-b8dc-dfe21666b046" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Access-Reader-Pro-2-15-9/e77b14b5-226a-4efa-b8dc-dfe21666b046</a></p><p><a href="https://community.ui.com/releases/UniFi-Access-G2-Reader-Pro-1-11-23-0/77ccbd66-43ee-48ed-8d23-c3b73f0b3c64" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Access-G2-Reader-Pro-1-11-23-0/77ccbd66-43ee-48ed-8d23-c3b73f0b3c64</a></p><p><a href="https://community.ui.com/releases/UniFi-Access-G3-Reader-Pro-1-11-22-0/36dca6a6-9e81-4866-81a2-15564f152cd7" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Access-G3-Reader-Pro-1-11-22-0/36dca6a6-9e81-4866-81a2-15564f152cd7</a></p><p><a href="https://community.ui.com/releases/UniFi-Access-Intercom-1-8-22-0/b8ab8c22-2409-4634-8443-21d726ff48eb" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Access-Intercom-1-8-22-0/b8ab8c22-2409-4634-8443-21d726ff48eb</a></p><p><a href="https://community.ui.com/releases/UniFi-Access-G3-Intercom-1-8-22-0/f4ac029c-b837-4bf9-853a-efa309971e44" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Access-G3-Intercom-1-8-22-0/f4ac029c-b837-4bf9-853a-efa309971e44</a></p><p><a href="https://community.ui.com/releases/UniFi-Access-Intercom-Viewer-1-4-39/d7c04f1e-4438-4c66-8f13-93a4e93cbbab" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Access-Intercom-Viewer-1-4-39/d7c04f1e-4438-4c66-8f13-93a4e93cbbab</a></p>]]></description>
            <link>https://community.ui.com/releases/Security-Advisory-Bulletin-051-051/583fa6e1-3d85-42ec-a453-651d1653c9b3</link>
            <guid isPermaLink="false">583fa6e1-3d85-42ec-a453-651d1653c9b3</guid>
            <category><![CDATA[unifi-access]]></category>
            <category><![CDATA[security]]></category>
            <dc:creator><![CDATA[UI-Marcus]]></dc:creator>
            <pubDate>Wed, 16 Jul 2025 15:17:52 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Security Advisory Bulletin 050]]></title>
            <description><![CDATA[<h2>Overview</h2><p>Published: July 14, 2025</p><p>Version: 1.0</p><p>Revision: 1.0</p><p><strong>&nbsp;</strong></p><p>An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.10.4 and earlier) could allow a Command Injection by a malicious actor with access to EdgeSwitch adjacent network.</p><p>&nbsp;&nbsp;</p><p><strong>Affected Products:</strong></p><p>EdgeMAX EdgeSwitch (Version 1.10.4 and earlier)&nbsp;</p><p>&nbsp;&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update the EdgeMAX EdgeSwitch to <strong>Version 1.11.0 or later</strong>.</p><p>&nbsp;&nbsp;</p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>7.5 High</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" rel="noopener noreferrer" target="_blank">CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a></p><p><strong>CVE: </strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-27211" rel="noopener noreferrer" target="_blank">CVE-2025-27211</a> (Jeff Barbi)</p><p>&nbsp;</p><p><strong>Reference Links:</strong></p><p><a href="https://community.ui.com/releases/EdgeMAX-EdgeSwitch-1-11-0/8b84659e-8193-4b2d-b905-cb1ceb06097b" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/EdgeMAX-EdgeSwitch-1-11-0/8b84659e-8193-4b2d-b905-cb1ceb06097b</a></p>]]></description>
            <link>https://community.ui.com/releases/Security-Advisory-Bulletin-050-050/f82b1701-58a1-4b7d-9e20-82d50e3e1961</link>
            <guid isPermaLink="false">f82b1701-58a1-4b7d-9e20-82d50e3e1961</guid>
            <category><![CDATA[security]]></category>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[UI-Marcus]]></dc:creator>
            <pubDate>Mon, 14 Jul 2025 21:25:49 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Security Advisory Bulletin 049]]></title>
            <description><![CDATA[<h2>Overview</h2><p>Published: July 7, 2025</p><p>Version: 1.1</p><p>Revision: 1.1</p><p><strong>&nbsp;</strong></p><p>A misconfigured query in UniFi Network (v9.0.108 and earlier) could allow users to authenticate to Enterprise WiFi or VPN Server (l2tp and OpenVPN) using a device’s&nbsp;MAC address from 802.1X or MAC Authentication, if both services are enabled and share the same RADIUS profile.</p><p>&nbsp;</p><p><strong>Affected Products:</strong></p><p>UniFi Network application (Version 9.0.108 and earlier)&nbsp;</p><p>&nbsp;</p><p><strong>Mitigation:</strong></p><p>Update the UniFi Network application to <strong>Version 9.0.114 or later</strong>.</p><p><strong>&nbsp;</strong></p><p><strong>Impact:</strong></p><p><strong>CVSS v3.0 Severity and Metrics:</strong></p><p><strong>Base Score: </strong>6.8 Medium</p><p><strong>Vector:&nbsp;</strong></p><p><strong>CVSS:</strong> <a href="https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N" rel="noopener noreferrer" target="_blank">CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N</a></p><p><strong>CVE: </strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-24292" rel="noopener noreferrer" target="_blank">CVE-2025-24292</a> (Kent Seymour)</p><p>&nbsp;</p><p><strong>Reference Links:</strong></p><p><a href="https://community.ui.com/releases/UniFi-Network-Application-9-0-114/35b6e9ac-f63d-46c9-bbbe-74a4a61ac95f" rel="noopener noreferrer" target="_blank">https://community.ui.com/releases/UniFi-Network-Application-9-0-114/35b6e9ac-f63d-46c9-bbbe-74a4a61ac95f</a></p>]]></description>
            <link>https://community.ui.com/releases/Security-Advisory-Bulletin-049-049/7a019b27-6c77-4500-bec8-596cd87c9292</link>
            <guid isPermaLink="false">7a019b27-6c77-4500-bec8-596cd87c9292</guid>
            <category><![CDATA[security]]></category>
            <category><![CDATA[unifi-network]]></category>
            <dc:creator><![CDATA[UI-Marcus]]></dc:creator>
            <pubDate>Wed, 18 Jun 2025 14:39:17 GMT</pubDate>
        </item>
    </channel>
</rss>