Three Critical Ubiquiti UniFi Vulnerabilities: Exposure and Response
Ubiquiti disclosed three CVSS 10.0 vulnerabilities affecting UniFi Protect, UniFi OS, and UniFi Talk. This analysis maps each network-reachable attack path to the affected releases, fixed versions, and a practical validation sequence.

Ubiquiti Security Advisory Bulletin 067 covers 22 vulnerabilities across the UniFi portfolio. Three of them—CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554—carry a CVSS 3.1 base score of 10.0. All three begin with network access to the affected target and require neither prior privileges nor user interaction. Their vulnerable components and outcomes differ, so treating the bulletin as a single universal update can leave systems behind.
The Protect and Talk flaws are input-validation weaknesses that can lead to command injection on the host device. The UniFi OS flaw mishandles CRLF sequences and can bypass authentication. Operators should map the application or device, the running version, and the relevant release track before scheduling changes.
Shared attack conditions
Ubiquiti assigned the same vector to all three issues: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. They are network reachable, low complexity, require no privileges or user action, cross a security scope boundary, and can have high confidentiality, integrity, and availability impact. Exposure reviews therefore need to include internal routes, remote-access paths, management VLANs, and site-to-site connections—not only public interfaces.

UniFi Protect command injection — CVE-2026-77537
CVE-2026-77537 is an improper input-validation flaw in UniFi Protect Application. An actor with network access can use it to inject commands on the host device. Ubiquiti lists UniFi Protect Application 7.1.87 and earlier as affected and recommends version 7.2.105 or later.
Protect changes should be validated against video operations. Record camera connectivity and recording status before the maintenance window. After updating, check the installed application version, administrator access, live streams, recording continuity, event search, and alert delivery. A successful installer message alone does not verify that the video workflow is healthy.
UniFi OS authentication bypass — CVE-2026-77550
CVE-2026-77550 is an improper neutralization of CRLF sequences in certain UniFi OS devices and instances. Crafted network input can cause message boundaries to be interpreted incorrectly and bypass authentication. Unlike the two command-injection flaws, this issue targets the management authentication boundary.
The affected list spans UniFi OS Server 5.1.21 and earlier; Cloud Keys, NVR and Enterprise NVR systems, Enterprise NAS and NAS, Dream Machines, Enterprise Firewall Core, Dream Routers, Enterprise Fortress Gateway, Cloud Gateways, Dream Wall, and Express 7 at 5.1.26 and earlier; and Express 4.0.16 and earlier. The breadth of this list makes role-based asset inventory essential.
The fixed targets are also product specific: UniFi OS Server 5.1.37 or later; 5.1.31 or later for Cloud Keys and most gateway, NVR, Enterprise NAS, and Express 7 products; 5.1.32 or later for Network Attached Storage; and 4.0.17 or later for Express. Track the product family, current release, target release, and result on the same inventory row rather than applying one version number across the estate.
UniFi Talk command injection — CVE-2026-77554
CVE-2026-77554 is an improper input-validation issue in UniFi Talk Application that can lead to command execution on the host device. Versions 5.2.7 and earlier are affected, and Ubiquiti recommends 5.3.2 or later. It shares the unauthenticated, network-reachable conditions of the Protect flaw but applies to the voice-service application.
Schedule Talk changes around calling requirements and emergency contact paths. Capture handset registration and representative call routes before the update. Afterward, verify the application version, administrator login, phone registration, inbound and outbound calling, extension calls, and voice quality.
Inventory and prioritization
Map the three CVEs by product role, execution location, running version, and reachable network. Protect and Talk may run on the same console while maintaining separate application versions. UniFi OS targets vary by hardware family, so include branch Cloud Keys, NVRs, Dream Machines, NAS devices, and Express products rather than relying only on a central console view.
Prioritize devices whose management plane is reachable from broad network segments, remote-support VPNs, site-to-site tunnels, or user networks. Narrowing access can reduce exposure before maintenance, but it does not replace the fixed release. Recheck the allowed management paths after the change so temporary exceptions do not remain.

Change and completion checks
- Inventory the execution location and version of Protect, UniFi OS, and Talk.
- Map the network paths that can reach each management interface or application and restrict unnecessary access.
- Back up configuration under the organization’s change procedure and reserve service-specific maintenance windows.
- Install Protect 7.2.105 or later, the correct UniFi OS release for each product family, and Talk 5.3.2 or later.
- Confirm versions and administrator access, then test video recording, networking, storage, phone registration, and calls as applicable.
Record the asset identifier, before-and-after versions, change time, owner, and functional test results. For CVE-2026-77550 in particular, compare the total device count with the number that reached the correct product-specific target. The evidence cutoff for this analysis is August 27, 2026 at 14:00 KST.
Sources reviewed
- Security Advisory Bulletin 067Ubiquiti · Official source
- CVE-2026-77537 RecordCVE Program · Official source
- CVE-2026-77550 RecordCVE Program · Official source
SECUFOCUS NOW reorganized and analyzed the material above. This article does not replace the original sources.



Comments
No comments yet.