ALITEQ.

Ubiquiti just shipped three perfect-10 security bugs in one bulletin and one needs zero password

UniFi Protect, UniFi OS and UniFi Talk each got their own maximum-severity flaw this week — the fourth time this year a Ubiquiti bug has hit a perfect 10.

Ravi MalhotraUpdated 1h ago7 min readWeb story
A Ubiquiti UniFi Dream Machine network appliance, the kind of device affected by the newly patched UniFi OS vulnerability

Ubiquiti published Security Advisory Bulletin 067 on August 26, and it's the ugliest one the company has shipped all year. Twenty-two vulnerabilities across the UniFi product line, 21 of them critical, and three sitting at a perfect CVSS 10.0 — meaning an attacker needs no password, no user interaction, and barely any skill to walk in the front door. This isn't one bad patch in one app. It's three separate maximum-severity bugs, in three separate products, disclosed on the same day.

Three perfect scores, three different products

What makes this bulletin worse than a normal critical-patch Tuesday is the spread. UniFi Protect is the camera and doorbell platform — the thing storing your actual security footage. UniFi Talk is a VoIP phone system bolted onto the same ecosystem. And UniFi OS is the console underneath both of them, the layer that boots the Dream Machine or Cloud Gateway you plugged in and forgot about. A bug in one app is a bad week. A perfect-10 in the OS layer means everything sitting on top of it inherits the exposure.

What's affected, what's fixed

CVE-2026-77537

CVE
UniFi Protect
Product
Unauthenticated compromise via improper input validation
What it does
Update to 7.2.105+

CVE-2026-77550

CVE
UniFi OS
Product
CRLF injection → remote auth bypass on the console
What it does
Update UniFi OS / console firmware

CVE-2026-77554

CVE
UniFi Talk
Product
Command injection via input validation flaw
What it does
Update to 5.3.2+

The one I'd lose sleep over: CVE-2026-77550

My honest take: the Protect and Talk bugs are bad, but CVE-2026-77550 is the one that actually scares me, because it isn't scoped to one app you could just disable. CRLF injection against UniFi OS means an attacker can smuggle extra headers or commands into requests the console trusts, and use that to skip the login screen for the entire management layer — the same console that holds your network topology, your camera feeds, your VoIP call logs, and every other UniFi service you've bolted on. Compromise the OS and you don't need to separately break Protect or Talk. You already own the box they're running on.

Networking equipment in a server rack, illustrating the enterprise and prosumer infrastructure UniFi OS runs on
UniFi OS is the console layer underneath every other UniFi app — a bypass here doesn't stay contained to one product. · Unsplash

A pattern, not a one-off

Ubiquiti's disclosure cadence this year reads like a slow-motion warning: a single CVSS 10.0 in March, another in May, another in July, and now three at once in August. Ubiquiti is far from alone here — 2026 has been a brutal year for perfect-10 bugs in network-facing appliances generally, from Cisco's own Crosswork platform shipping five CVSS 10.0 bugs it found itself to N-able's N-central RMM tool getting hit by an actively-exploited auth bypass to VMware vCenter's reverse-SSH zero-day hitting 47 countries. The common thread isn't sloppiness at any one vendor — it's that management consoles and appliance OSes have become the preferred target, because compromising one gets an attacker everything running underneath it, in one move.

Open the UniFi console and check your UniFi OS / console firmware version, plus Protect and Talk app versions separately — they patch independently.

Update UniFi Protect Application to 7.2.105 or later.

Update UniFi Talk Application to 5.3.2 or later.

Update UniFi OS / console firmware to the latest build Ubiquiti has published for your hardware.

If your console's management port is reachable from the open internet rather than only your LAN or VPN, that's the exposure that turns a CVSS 10.0 from theoretical into actively probed — lock it down regardless of patch status.

Is this being exploited right now?
Ubiquiti hasn't confirmed active exploitation of these three specific CVEs, and it didn't comment when asked directly. That said, a separate set of Ubiquiti vulnerabilities was added to CISA's Known Exploited Vulnerabilities catalog just two months earlier, so treat 'not yet confirmed' as 'not yet publicly confirmed,' not as 'safe.'
What does a CVSS 10.0 actually mean here?
The maximum possible severity score: network-reachable, no authentication required, no user interaction required, and low attack complexity. All three of these bugs qualify on every count.
Does this affect home users or just businesses?
Both. UniFi's Dream Machine and Cloud Gateway lines are widely sold to home and prosumer users, not just enterprise IT — if you're running any UniFi console, all three CVEs are relevant to you.
Do I need to do anything if auto-update is enabled?
Check anyway. UniFi OS, Protect and Talk update on separate schedules and auto-update can lag or be disabled per-app — confirm all three show the patched version numbers above rather than assuming one update covered everything.

Ubiquiti's advisory shipped without much commentary beyond the fix list, which is standard for the company and not itself a red flag. But the track record on UniFi-specific CVEs this year says the gap between disclosure and active scanning has been shrinking, not growing. If you're running UniFi gear at home and haven't opened the console in a few months, this is the week to do it — not because there's proof anyone's exploiting these three yet, but because by the time there is, you want to already be patched.

Hardware Editor

Ravi Malhotra

Ravi has been building and taking apart PCs since the single-core days — his idea of a good weekend is a repaste and a spreadsheet full of thermals. He covers GPUs, CPUs and the build decisions that actually move frame rates, and he'd rather hand you a benchmark than a press release.

Work out the hardware

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading