Multiple Critical Vulnerabilities in Ubiquiti Unifi OS (CVE-2026-33000, CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, CVE-2026-34911)

A series of critical vulnerabilities—including three with “perfect” CVSSv3 10.0—can lead to account takeover and command injection on unpatched Unifi OS systems.

Ubiquiti’s advisory has details:

https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b

Patches are available and should be deployed ASAP.

3 Likes

I’m glad I’ve been avoiding that pop up to “upgrade” to unifi server for a few months now.

BishopFox has published a writeup on exploiting these vulnerabilities. Hope y’all patched!