Ubiquiti has patched 21 critical-severity vulnerabilities spanning nearly its entire UniFi product line, warning that attackers with only network access could chain the flaws to bypass authentication, inject commands, and seize full control of routers, cameras, access-control systems, and cloud gateways.
The disclosures, tracked under a fresh batch, arrive months after Ubiquiti’s earlier Security Advisory Bulletin 064 fixed three maximum-severity, actively exploited flaws in UniFi OS that CISA later added to its Known Exploited Vulnerabilities catalog.
This new round confirms that UniFi’s sprawling ecosystem, which includes network, security, access, and communications products used by homes, enterprises, and managed service providers, remains a persistent target for researchers and threat actors alike.
Command Injection Vulnerabilities Patched
The bulk of the flaws stem from improper input validation that lets attackers execute arbitrary commands on host devices. UniFi Protect Application, the video surveillance backbone, carries the most severe entries: CVE-2026-77537 scores a perfect 10.0 and requires no privileges at all, while CVE-2026-77533 needs only low-level network access.
Both are fixed in version 7.2.105. Similar command injection issues hit UniFi OS Server (patched in 5.1.37), UniFi Network Application (10.5.67), UniFi Access Application (4.3.5), UniFi Talk Application (5.3.2, also a 10.0-rated flaw), the UID Enterprise Agent (1.62.1), and the UniFi Enterprise Audio/Video Bridge (1.0.11).
Researchers Brandon Rossi and the team at Catchify Security are credited with reporting several of the most severe bugs, alongside independent contributors like bugbunny.ai and Ben Koo.
Privilege Escalation and Authentication Bypass Vulnerability
Beyond command injection, several improper access control flaws allow low-privileged network attackers to escalate to administrator-level control over UniFi OS devices, a category covering Cloud Keys, Network Video Recorders, Dream Machines, Dream Routers, Enterprise Fortress Gateways, and Cloud Gateways.
These are addressed across versions 5.1.31 through 5.1.37 depending on the device family. Two authentication bypass flaws, CVE-2026-77549 and CVE-2026-77550, exploit improper neutralization of CRLF sequences, letting attackers on the network sidestep login controls entirely; the latter scores a maximum of 10.0 and was reported by a trio of researchers at TurtleSec.
| CVE ID | Affected Product | Version(s) Affected | Vulnerability Type | Fixed Version |
|---|---|---|---|---|
| CVE-2026-77533 | UniFi Protect Application | 7.1.87 and earlier | Improper Input Validation → Command Injection | 7.2.105 |
| CVE-2026-77534 | UniFi OS (Server, Cloud Keys, NVRs, NAS, Dream Machines/Routers, Fortress Gateway, Cloud Gateways, Dream Wall, Express 7) | Server 5.1.21 / others 5.1.26 and earlier | Improper Access Control → Privilege Escalation | Server 5.1.37; most devices 5.1.31; NAS 5.1.32 |
| CVE-2026-77535 | UniFi Network Application | 10.4.57 and earlier | Improper Input Validation → Command Injection (adopted device) | 10.5.67 |
| CVE-2026-77536 | UniFi OS (same device family as above) | Server 5.1.21 / others 5.1.26 and earlier | Improper Access Control → Privilege Escalation | Server 5.1.37; most devices 5.1.31; NAS 5.1.32 |
| CVE-2026-77537 | UniFi Protect Application | 7.1.87 and earlier | Improper Input Validation → Command Injection | 7.2.105 |
| CVE-2026-77538 | UniFi Connect Application | 3.24.20 and earlier | Improper Access Control → Privilege Escalation (chainable) | 3.24.22 |
| CVE-2026-77539 | UniFi OS Server | 5.1.21 and earlier | Improper Input Validation → Command Injection | 5.1.37 |
| CVE-2026-77540 | UniFi OS Server | 5.1.21 and earlier | Improper Input Validation → Command Injection | 5.1.37 |
| CVE-2026-77541 | UniFi Network Application | 10.4.57 and earlier | Improper Access Control → Privilege Escalation | 10.5.67 |
| CVE-2026-77542 | UID Enterprise Agent | 1.61.8 and earlier | Improper Input Validation → Command Injection | 1.62.1 |
| CVE-2026-77543 | UniFi Access Application | 4.3.3 and earlier | Improper Input Validation → Command Injection | 4.3.5 |
| CVE-2026-77545 | UniFi OS (same device family as above) | Server 5.1.21 / others 5.1.26 and earlier | Active Debug Code → Privilege Escalation | Server 5.1.37; most devices 5.1.31; NAS 5.1.32 |
| CVE-2026-77546 | UniFi Access Application | 4.3.3 and earlier | Improper Input Validation → Command Injection | 4.3.5 |
| CVE-2026-77547 | UniFi Access Application | 4.3.3 and earlier | Improper Input Validation → Command Injection | 4.3.5 |
| CVE-2026-77548 | UniFi Protect Application | 7.1.87 and earlier | Improper Input Validation → Command Injection | 7.2.105 |
| CVE-2026-77549 | UniFi OS (Server, devices, Express) | Server 5.1.21 / devices 5.1.26 / Express 4.0.16 and earlier | Improper Neutralization of CRLF → Authentication Bypass | Server 5.1.37; devices 5.1.31/5.1.32; Express 4.0.17 |
| CVE-2026-77550 | UniFi OS (Server, devices, Express) | Server 5.1.21 / devices 5.1.26 / Express 4.0.16 and earlier | Improper Neutralization of CRLF → Authentication Bypass | Server 5.1.37; devices 5.1.31/5.1.32; Express 4.0.17 |
| CVE-2026-77551 | UniFi Connect Display Cast Pro | 1.0.108 and earlier | Improper Access Control → Privilege Escalation | 1.0.111 |
| CVE-2026-77552 | UniFi Enterprise Audio/Video Bridge | 1.0.10 and earlier | Improper Input Validation → Command Injection | 1.0.11 |
| CVE-2026-77553 | UniFi Access Application | 4.3.3 and earlier | Improper Access Control → Privilege Escalation | 4.3.5 |
| CVE-2026-77554 | UniFi Talk Application | 5.2.7 and earlier | Improper Input Validation → Command Injection | 5.3.2 |
| CVE-2026-77557 | UniFi Protect AI Key | 2.1.3 and earlier | Improper Access Control → Privilege Escalation | 2.2.6 |
Additional privilege escalation bugs touch the UniFi Connect Application, UniFi Connect Display Cast Pro, UniFi Access Application, and the UniFi Protect AI Key, an edge AI module for camera analytics.
Every flaw in this disclosure carries a CVSS base score between 8.2 and a perfect 10.0, and most require nothing more than network reachability to exploit, making unpatched, internet-facing UniFi deployments especially dangerous.
Given that Ubiquiti’s UniFi OS has already seen active exploitation earlier in 2026, security teams should treat these updates as urgent rather than routine.
Ubiquiti is urging all customers to immediately update UniFi Protect to 7.2.105, UniFi OS Server to 5.1.37, UniFi Network Application to 10.5.67, UniFi Access to 4.3.5, UniFi Talk to 5.3.2, UniFi Connect to 3.24.22, the UID Enterprise Agent to 1.62.1, UniFi Connect Display Cast Pro to 1.0.111, the Enterprise Audio/Video Bridge to 1.0.11, and the Protect AI Key to 2.2.6.
Organizations running UniFi OS on Cloud Keys, NVRs, NAS units, Dream Machines, or Dream Routers should confirm firmware matches the vendor’s latest builds for each specific hardware family, since patch levels vary by device.
Given the pattern of chained exploitation seen in prior UniFi advisories, defenders should also isolate management interfaces from the public internet and enforce multi-factor authentication wherever administrative access cannot be fully restricted.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

