UniFi Protect, UniFi OS and UniFi Talk each got their own maximum-severity flaw this week — the fourth time this year a Ubiquiti bug has hit a perfect 10.
Ubiquiti published Security Advisory Bulletin 067 on August 26, and it's the ugliest one the company has shipped all year. Twenty-two vulnerabilities across the UniFi product line, 21 of them critical, and three sitting at a perfect CVSS 10.0 — meaning an attacker needs no password, no user interaction, and barely any skill to walk in the front door. This isn't one bad patch in one app. It's three separate maximum-severity bugs, in three separate products, disclosed on the same day.
Three perfect scores, three different products
What makes this bulletin worse than a normal critical-patch Tuesday is the spread. UniFi Protect is the camera and doorbell platform — the thing storing your actual security footage. UniFi Talk is a VoIP phone system bolted onto the same ecosystem. And UniFi OS is the console underneath both of them, the layer that boots the Dream Machine or Cloud Gateway you plugged in and forgot about. A bug in one app is a bad week. A perfect-10 in the OS layer means everything sitting on top of it inherits the exposure.
What's affected, what's fixed
CVE-2026-77537
CVE
UniFi Protect
Product
Unauthenticated compromise via improper input validation
What it does
Update to 7.2.105+
CVE-2026-77550
CVE
UniFi OS
Product
CRLF injection → remote auth bypass on the console
What it does
Update UniFi OS / console firmware
CVE-2026-77554
CVE
UniFi Talk
Product
Command injection via input validation flaw
What it does
Update to 5.3.2+
CVE
Product
What it does
Fix
CVE-2026-77537
UniFi Protect
Unauthenticated compromise via improper input validation
Update to 7.2.105+
CVE-2026-77550
UniFi OS
CRLF injection → remote auth bypass on the console
Update UniFi OS / console firmware
CVE-2026-77554
UniFi Talk
Command injection via input validation flaw
Update to 5.3.2+
The one I'd lose sleep over: CVE-2026-77550
My honest take: the Protect and Talk bugs are bad, but CVE-2026-77550 is the one that actually scares me, because it isn't scoped to one app you could just disable. CRLF injection against UniFi OS means an attacker can smuggle extra headers or commands into requests the console trusts, and use that to skip the login screen for the entire management layer — the same console that holds your network topology, your camera feeds, your VoIP call logs, and every other UniFi service you've bolted on. Compromise the OS and you don't need to separately break Protect or Talk. You already own the box they're running on.
UniFi OS is the console layer underneath every other UniFi app — a bypass here doesn't stay contained to one product. · Unsplash
Open the UniFi console and check your UniFi OS / console firmware version, plus Protect and Talk app versions separately — they patch independently.
Update UniFi Protect Application to 7.2.105 or later.
Update UniFi Talk Application to 5.3.2 or later.
Update UniFi OS / console firmware to the latest build Ubiquiti has published for your hardware.
If your console's management port is reachable from the open internet rather than only your LAN or VPN, that's the exposure that turns a CVSS 10.0 from theoretical into actively probed — lock it down regardless of patch status.
Is this being exploited right now?
Ubiquiti hasn't confirmed active exploitation of these three specific CVEs, and it didn't comment when asked directly. That said, a separate set of Ubiquiti vulnerabilities was added to CISA's Known Exploited Vulnerabilities catalog just two months earlier, so treat 'not yet confirmed' as 'not yet publicly confirmed,' not as 'safe.'
What does a CVSS 10.0 actually mean here?
The maximum possible severity score: network-reachable, no authentication required, no user interaction required, and low attack complexity. All three of these bugs qualify on every count.
Does this affect home users or just businesses?
Both. UniFi's Dream Machine and Cloud Gateway lines are widely sold to home and prosumer users, not just enterprise IT — if you're running any UniFi console, all three CVEs are relevant to you.
Do I need to do anything if auto-update is enabled?
Check anyway. UniFi OS, Protect and Talk update on separate schedules and auto-update can lag or be disabled per-app — confirm all three show the patched version numbers above rather than assuming one update covered everything.
Ubiquiti's advisory shipped without much commentary beyond the fix list, which is standard for the company and not itself a red flag. But the track record on UniFi-specific CVEs this year says the gap between disclosure and active scanning has been shrinking, not growing. If you're running UniFi gear at home and haven't opened the console in a few months, this is the week to do it — not because there's proof anyone's exploiting these three yet, but because by the time there is, you want to already be patched.