Ubiquiti just shipped three perfect-10 security bugs in one bulletin — and one needs zero password

UniFi Protect, UniFi OS and UniFi Talk each got their own maximum-severity flaw this week — the fourth time this year a Ubiquiti bug has hit a…

Aliteq
Ravi Malhotra · Hardware Editor

The three CVSS 10.0 bugs

CVE-2026-77537 — UniFi Protect Application (video surveillance), improper input validation, unauthenticated. Affects builds below 7.2.105, fixed in 7.2.105.

The three CVSS 10.0 bugs

CVE-2026-77550 — UniFi OS itself, CRLF injection that lets a remote attacker bypass authentication entirely on the console layer every other app runs on top of.

The three CVSS 10.0 bugs

CVE-2026-77554 — UniFi Talk (the VoIP phone app), command injection via bad input validation. Affects builds below 5.3.2, fixed in 5.3.2.

The three CVSS 10.0 bugs

This is Ubiquiti's fourth CVSS 10.0 disclosure of 2026 — after single perfect-10s in March, May and July — but the first time three have landed in one bulletin.

The three CVSS 10.0 bugs

Ubiquiti has not confirmed active exploitation of any of the three, though it also declined to comment on the question when asked.

This isn't Ubiquiti's first perfect 10 this year

Two months before this bulletin, CISA added a separate set of three actively-exploited Ubiquiti vulnerabilities to its Known Exploited Vulnerabilities catalog. Different CVEs, same pattern: Ubiquiti…

Aliteq

Read the full story

Ubiquiti just shipped three perfect-10 security bugs in one bulletin — and one needs zero password

Read the full story on Aliteq