- The Mess: Ubiquiti patched 22 vulnerabilities across its UniFi ecosystem, including three maximum-severity flaws affecting UniFi Protect, UniFi OS and UniFi Talk. The three bugs are tracked as CVE-2026-77537, CVE-2026-77550 and CVE-2026-77554.
- The Damage: The flaws can allow attackers with network access to execute commands, bypass authentication or compromise affected systems without credentials or user interaction. More than 100,000 UniFi OS instances are currently visible online, according to Censys data cited by researchers.
- The Fix: Update UniFi Protect to 7.2.105+, UniFi Talk to 5.3.2+ and apply the relevant UniFi OS updates from Security Advisory Bulletin 067.
Ubiquiti just dropped a security bulletin that is much bigger than the headline suggests.
22 vulnerabilities.
21 rated Critical.
Three of them sit at the maximum end of the severity scale.
And they hit three completely different parts of the UniFi ecosystem.
That’s a bad combination for anyone running UniFi across an office, retail network, school or multi-site environment.
Three Bugs. Three Attack Surfaces.
The first vulnerability, CVE-2026-77537, affects UniFi Protect.
Protect manages cameras, video recordings and surveillance infrastructure.
The flaw is caused by improper input validation and can lead to command injection on the host device. Ubiquiti rates it 9.9 Critical, while NVD assigns a CVSS 10.0 score.
The fix is UniFi Protect 7.2.105 or later.
The second vulnerability, CVE-2026-77550, is different.
It affects UniFi OS and uses CRLF injection to bypass authentication.
An attacker with network access can send specially crafted input that interferes with authentication handling.
No password is required.
No user interaction is required.
And once authentication is bypassed, the management layer itself becomes the target.
Then there is CVE-2026-77554.
This one affects UniFi Talk, Ubiquiti’s VoIP platform.
It is another improper input validation issue that can lead to command injection on the underlying host.
The fix is UniFi Talk 5.3.2 or later.
The Problem Is the Breadth
This isn’t one vulnerable web application.
It’s an ecosystem.
Protect.
OS.
Talk.
And the same security bulletin covers another 19 vulnerabilities across UniFi products, including network management, access control, storage, gateways and surveillance hardware.
That makes a simple “we patched UniFi” statement almost meaningless.
Administrators need to know which components are actually installed.
Updating the UniFi OS layer does not automatically mean every application running on top of it has received the relevant fix.
Internet Exposure Makes This Worse
Censys data cited by BleepingComputer showed more than 100,000 UniFi OS instances visible from the Internet.
That doesn’t mean 100,000 vulnerable systems.
Some may be historical results, honeypots or already patched deployments.
But the number demonstrates the size of the potential attack surface.
And UniFi management interfaces are attractive targets.
They control infrastructure.
They know about devices.
They often have privileged access.
They can sit directly at the edge of a network.
That’s exactly where attackers want a foothold.
No Exploit Yet Doesn’t Mean Safe
As of the disclosure, Ubiquiti had not confirmed exploitation in the wild for these three vulnerabilities.
That’s good news.
It is also temporary.
Earlier this year, other maximum-severity UniFi vulnerabilities were patched and later observed being actively exploited. BleepingComputer reported that attackers used those flaws to build chains capable of achieving elevated remote code execution.
So the correct question isn’t:
“Has someone exploited this yet?”
It’s:
“How long do we want to wait?”
Patch Every Layer
Administrators should inventory:
- UniFi OS versions
- Protect versions
- Talk versions
- Internet-facing management interfaces
- Remote-access configuration
- Administrative accounts
Then apply Security Advisory Bulletin 067 across every affected component. Ubiquiti’s own bulletin lists the affected products and individual remediation versions.
If management interfaces don’t need to be reachable from the Internet, don’t expose them.
A firewall rule won’t fix the vulnerability.
But it can dramatically reduce the number of systems an attacker can reach while patching is underway.
Bugstoday Opinion
Three maximum-severity vulnerabilities in three different UniFi components is enough to make this more than another firmware update.
The interesting part isn’t the number 10.0.
It’s the architecture.
An attacker doesn’t necessarily need to compromise the router directly.
They can look at the surveillance layer.
The operating system.
The VoIP layer.
Different applications.
Different services.
Different doors into the same ecosystem.
And Ubiquiti has already shown earlier this year that critical UniFi vulnerabilities can move from disclosure to real-world exploitation.
Bugstoday verdict: don’t wait for these three CVEs to enter an attacker’s toolkit. If UniFi is running your cameras, network or phones, patch every affected component now.
Today’s Bugs. Tomorrow’s Breaches.




