Particle.news

Ubiquiti Issues Patches for Seven Critical UniFi Flaws

The updates close command‑injection and privilege‑escalation holes that leave many internet‑exposed UniFi systems at immediate risk.

Overview

  • Ubiquiti released updates on Wednesday that patch seven critical UniFi vulnerabilities, including CVE-2026-50746 which is fixed in UniFi Connect 3.4.20.
  • The bugs include command injection, authenticated SQL injection, SSRF, and improper access control flaws that Ubiquiti says six can be exploited with low complexity and no user interaction.
  • Threat scans show more than 100,000 UniFi OS instances are exposed online, with roughly 50,000 of those IPs located in the United States, increasing the chance of opportunistic compromise.
  • The U.S. Cybersecurity and Infrastructure Security Agency flagged related UniFi defects as weaponized in June and security researchers at Bishop Fox demonstrated multi-bug exploit chains and published detection scripts.
  • Network operators should install the vendor fixes, run published detection tools, and apply network‑level controls now to avoid service outages, data theft, or large‑scale device takeover by criminal or state actors.