Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-77550 (primary) + 11 related |
| Alert Source | GitHub Advisory - Critical vulnerability |
| CVE Year | 2026 |
| Publication Date | 2026-08-27 |
| Vendor | Ubiquiti |
| Product | UniFi OS and UniFi applications |
| CVSS Score | 10.0 (Critical) — highest in the bulletin |
| EPSS Score | No data for most; up to 1% for the oldest |
| CISA KEV | No |
| Ransomware | Not confirmed |
Consolidated entry. Ubiquiti disclosed 12 vulnerabilities at once, in a single bulletin. We cover them together because they affect the same platform and are removed by the same update — publishing twelve separate alerts would obscure the picture rather than clarify it.
Vulnerability Description
Source: NVD / Ubiquiti
Most severe: authentication bypass (CVSS 10.0)
CVE-2026-77550 — improper neutralization of CRLF sequences in certain devices running UniFi OS lets an attacker with network access bypass authentication to the device or instance. A score of 10.0 is the maximum on the CVSS scale.
CVE-2026-77549 (CVSS 9.0) — the same class of flaw (CRLF) leading to authentication bypass, under additional conditions.
Command execution on the device
- CVE-2026-77554 (10.0) — command injection in the UniFi Talk application, via improper input validation.
- CVE-2026-77552 (9.8) — command injection in the UniFi Enterprise Audio/Video Bridge.
- CVE-2026-77539 and CVE-2026-77540 (both 9.1) — command injection on the host through UniFi OS Server; require high privileges.
Privilege escalation
- CVE-2026-77553 (9.9) — UniFi Access: a low-privileged attacker escalates on the host device.
- CVE-2026-77536 and CVE-2026-77534 (both 9.9) — improper access control in UniFi OS devices; escalation from low privileges.
- CVE-2026-77557 (9.8) — UniFi Protect AI Key: privilege escalation on the device.
- CVE-2026-77541 (9.1) — UniFi Network Application: escalation within the application, requires high privileges.
- CVE-2026-77545 (9.0) — Active Debug Code left enabled in devices running UniFi OS.
Required Actions
- Update UniFi OS and every UniFi application in use (Network, Protect, Access, Talk) to the latest versions. Updating an application does not replace updating UniFi OS itself — these are separate components.
- Check whether the UniFi console is reachable from the internet. Remote management through Ubiquiti’s cloud does not require exposing the local interface.
- Pay particular attention to UniFi Access — this is a door access control system. Privilege escalation there means potential impact on physical security, not just network security.
- Verify that UniFi devices are in the asset inventory covered by your patching cycle. Network hardware tends to drop out of it, because “it works and nobody touches it”.
Who Is Affected?
The vulnerabilities affect devices running UniFi OS and the UniFi Network, Protect, Access and Talk applications from Ubiquiti.
UniFi is a widely adopted network platform in mid-size companies — access points, switches, gateways and management consoles. Beyond networking it also covers video surveillance (Protect), door access control (Access) and telephony (Talk).
That integration matters here: taking control of the UniFi platform in an organisation that uses it comprehensively grants simultaneous access to network infrastructure, camera recordings and the door-opening system. This bulletin deserves to be treated more seriously than a routine network hardware update.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
