ThreatBrief AI

Ubiquiti Warns of Critical UniFi Command-Injection Flaws

Ubiquiti patched 25 UniFi ecosystem vulnerabilities, including a CVSS 10.0 UniFi Connect command-injection flaw.

+ +

Published

Jul 09, 2026

Duration

4 min read

Risk Level

Critical

Why it matters

Ubiquiti’s UniFi stack often sits close to network management, physical security, building automation, and site operations. A maximum-severity command-injection issue in UniFi Connect therefore deserves fast exposure review even when the public advisory does not describe active exploitation. The main risk is not only the CVSS 10.0 score; it is the combination of network reachability, management-plane privileges, and the breadth of UniFi products covered by the same advisory wave.

What happened

Ubiquiti published Security Advisory Bulletin 066 on July 2, 2026, covering 25 vulnerabilities across UniFi Connect, Talk, Access, Protect, Network Application, UniFi OS, and related device families. BleepingComputer reported on July 8 that seven of the issues are critical and highlighted CVE-2026-50746, an improper access-control flaw in UniFi Connect Application 3.4.16 and earlier. Ubiquiti says a malicious actor with network access could exploit that flaw to execute command injection on the host device, and it instructs customers to update UniFi Connect Application to version 3.4.20 or later.

Technical details

The advisory’s highest-severity item is CVE-2026-50746, rated CVSS 10.0 with network attack vector, low attack complexity, no privileges required, and no user interaction. Ubiquiti also lists several other high-impact UniFi issues, including CVE-2026-50747 in UniFi Talk, CVE-2026-50748 and CVE-2026-54400 in UniFi Access, CVE-2026-54402 and CVE-2026-54403 in UniFi OS, and CVE-2026-54405 in UniFi Network Application. ThreatBrief is not publishing exploit steps; the defensive signal is that reachable UniFi management applications and appliances should be inventoried against the fixed versions in Bulletin 066.

Defender actions

Prioritize UniFi environments whose management interfaces are reachable from the internet, shared user networks, partner networks, or other lower-trust segments. Update UniFi Connect to 3.4.20 or later, UniFi Talk to 5.2.2 or later, UniFi Access to 4.2.29 or later, UniFi Network Application to 10.4.57 or later, and UniFi OS device families to the relevant 5.1.19-or-later guidance in Ubiquiti’s bulletin. Restrict management-plane access to dedicated administration networks or VPN paths, review logs for unexpected administrator activity, and treat unpatched exposed controllers as urgent until version checks confirm remediation.

Indicators

7 indicators · TLP:clear

cve · other · high conf

CVE-2026-50746

Ubiquiti UniFi ecosystem vulnerability listed in Security Advisory Bulletin 066.

Srcs: ubiquiti-bulletin-066
ubiquitiunifivulnerability

cve · other · high conf

CVE-2026-50747

Ubiquiti UniFi ecosystem vulnerability listed in Security Advisory Bulletin 066.

Srcs: ubiquiti-bulletin-066
ubiquitiunifivulnerability

cve · other · high conf

CVE-2026-50748

Ubiquiti UniFi ecosystem vulnerability listed in Security Advisory Bulletin 066.

Srcs: ubiquiti-bulletin-066
ubiquitiunifivulnerability

cve · other · high conf

CVE-2026-54400

Ubiquiti UniFi ecosystem vulnerability listed in Security Advisory Bulletin 066.

Srcs: ubiquiti-bulletin-066
ubiquitiunifivulnerability

cve · other · high conf

CVE-2026-54402

Ubiquiti UniFi ecosystem vulnerability listed in Security Advisory Bulletin 066.

Srcs: ubiquiti-bulletin-066
ubiquitiunifivulnerability

cve · other · high conf

CVE-2026-54403

Ubiquiti UniFi ecosystem vulnerability listed in Security Advisory Bulletin 066.

Srcs: ubiquiti-bulletin-066
ubiquitiunifivulnerability

cve · other · high conf

CVE-2026-54405

Ubiquiti UniFi ecosystem vulnerability listed in Security Advisory Bulletin 066.

Srcs: ubiquiti-bulletin-066
ubiquitiunifivulnerability