Ubiquiti has released security updates to address multiple critical vulnerabilities across its UniFi product line, including UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS. The flaws could allow attackers to achieve privilege escalation and arbitrary command execution on affected devices.
The vulnerabilities include CVE-2026-50746 (CVSS 10.0), an improper access control issue in UniFi Connect Application that could lead to command injection; CVE-2026-50747 (CVSS 9.9), authenticated SQL injection vulnerabilities in UniFi Talk Application; CVE-2026-50748 (CVSS 9.9), improper input validation in UniFi Access Application enabling command injection; CVE-2026-54400 (CVSS 9.1), improper access control in UniFi Access Application; CVE-2026-55115 (CVSS 9.9), a Server-Side Request Forgery (SSRF) vulnerability in UniFi Protect Application; CVE-2026-54402 (CVSS 9.9), improper input validation in UniFi OS leading to command injection; and CVE-2026-55116 (CVSS 9.0), improper access control in UniFi OS allowing unauthorized device changes.
While no active exploitation of these specific flaws has been reported, three previously disclosed UniFi OS vulnerabilities (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910) were flagged by CISA as weaponized in real-world attacks. Additionally, Russian state-sponsored threat actors have been observed using compromised Ubiquiti Edge OS routers in a botnet named MooBot, which was disrupted in a law enforcement operation in February 2024.
Users are strongly advised to update their UniFi applications and OS to the latest patched versions to mitigate these risks.
CVEs: CVE-2026-50746, CVE-2026-50747, CVE-2026-50748, CVE-2026-54400, CVE-2026-55115, CVE-2026-54402, CVE-2026-55116, CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, CVE-2026-55200, CVE-2026-46817
Attack groups: Russian state-sponsored threat actors
Malware: MooBot
Products: UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, UniFi OS, Ubiquiti Edge OS
Original source: thehackernews.com