Full Report
The communications product company disclosed 22 total Wednesday, all but one of which was rated “critical” at 9.0 or higher. The post Three 10.0 security flaws fixed across Ubiquiti’s UniFi line appeared first on CyberScoop.
Analysis Summary
# Vulnerability: Multiple Critical Flaws in Ubiquiti UniFi Product Line
## CVE Details
*Note: This advisory covers 22 vulnerabilities in total. The details below focus on the three maximum-severity flaws.*
* **CVE ID:** CVE-2026-77537, CVE-2026-77550, CVE-2026-77554
* **CVSS Score:** 10.0 (Critical)
* **CWE:** Improper Access Control
## Affected Systems
* **Products:** Ubiquiti UniFi line of products (Networking applications and devices).
* **Versions:** Specific vulnerable versions vary by component; users should refer to Security Advisory Bulletin 067.
* **Configurations:** Systems running affected UniFi software or firmware without the latest security updates.
## Vulnerability Description
The primary flaws (CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554) are categorized as **Improper Access Control**. These vulnerabilities allow an attacker to bypass intended security restrictions to gain unauthorized privileges on the affected device or application.
Of the 22 total vulnerabilities disclosed in this batch:
* 7 involve improper access control.
* Others include authentication bypass and arbitrary command execution.
* 21 of the 22 flaws are rated "Critical" (CVSS 9.0+).
## Exploitation
* **Status:** Not currently reported as exploited in the wild (per initial vendor disclosure); however, CISA recently added three *previous* Ubiquiti flaws to the Known Exploited Vulnerabilities (KEV) catalog, indicating the brand is a high-interest target for threat actors.
* **Complexity:** Not explicitly stated, though CVSS 10.0 typically implies low complexity.
* **Attack Vector:** Network (Remote).
## Impact
* **Confidentiality:** Total (High) - Attackers can gain full access to device data and credentials.
* **Integrity:** Total (High) - Attackers can modify configurations and run arbitrary commands.
* **Availability:** Total (High) - Attackers can gain administrative control, potentially bricking or disabling devices.
## Remediation
### Patches
Ubiquiti has released updates to address these vulnerabilities. Users are urged to update their UniFi OS and Application versions immediately.
* Refer to **Security Advisory Bulletin 067** for the specific firmware/software version mapping for your hardware.
### Workarounds
* Ensure management interfaces are not exposed to the public internet.
* Implement strict Firewall/ACL rules to limit access to UniFi controllers.
* Enable Multi-Factor Authentication (MFA) for all administrative accounts.
## Detection
* **Indicators of Compromise:** Monitor for unauthorized administrative account creation, unusual configuration changes, or unrecognized IP addresses accessing the management console.
* **Detection methods and tools:** Audit system logs for access control bypass attempts and review CISA’s KEV catalog for related Ubiquiti exploitation patterns.
## References
* Ubiquiti Security Advisory Bulletin 067: hxxps[://]community[.]ui[.]com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9
* CVE Record (77537): hxxps[://]www[.]cve[.]org/CVERecord?id=CVE-2026-77537
* CVE Record (77550): hxxps[://]www[.]cve[.]org/CVERecord?id=CVE-2026-77550
* CVE Record (77554): hxxps[://]www[.]cve[.]org/CVERecord?id=CVE-2026-77554
* CyberScoop Article: hxxps[://]cyberscoop[.]com/ubiquiti-unifi-critical-vulnerabilities-patched/