Skip to main content

Share story

Security

Ubiquiti patches critical UniFi flaws including CVSS 10.0 command injection across Connect, Talk, Access, Protect and OS

Ubiquiti patches critical UniFi flaws including CVSS 10.0 command injection across Connect, Talk, Access, Protect and OS Image: Primary
Ubiquiti has shipped security updates addressing multiple critical flaws in UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect and UniFi OS, The Hacker News reported on Jul 08, 2026. According to the report, which linked to a Ubiquiti security advisory on community.ui.com, the issues could result in privilege escalation and arbitrary command execution. The most severe is CVE-2026-50746, an improper access control vulnerability in the UniFi Connect Application with a CVSS score of 10.0. An attacker with network access could use it to execute a command injection on the host device. It affects versions 3.4.16 and earlier and is fixed in version 3.4.20. The Hacker News also listed CVE-2026-50747, authenticated SQL injection flaws in UniFi Talk with a CVSS score of 9.9, fixed in version 5.2.2; UniFi Access issues CVE-2026-50748 (CVSS score: 9.9) and CVE-2026-54400 (CVSS score: 9.1), fixed in version 4.2.29; UniFi Protect Server-Side Request Forgery CVE-2026-55115 with a CVSS score of 9.9, fixed in version 7.1.83; and UniFi OS flaws CVE-2026-54402 (CVSS score: 9.9) and CVE-2026-55116 (CVSS score: 9.0), fixed in version 5.1.19. There is no evidence that the flaws have been exploited in the wild, the report said.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Science Security
Science Security

Preprint finds sensitive-topic leakage in AI model routing logs

Researchers report in a preprint that logs recording which AI model handles a request can expose sensitive-topic patterns even when content logging is disabled. Their studies used 1.7 million real requests and tested systems that ...

Security Infrastructure
Security Infrastructure

IDCF Cloud ransomware attack disrupts companies and local governments

A ransomware attack disrupted IDCF Cloud's East Japan Region 1 on October 7, affecting websites and services used by companies and local governments. A note article citing ITmedia and Nikkei reports said unauthorized access began ...

Security AI
Security AI

AWS releases instructions for evidence-based AI vulnerability triage

AWS released a steering file that directs AI coding assistants to verify code paths before reporting vulnerabilities and to incorporate deployment controls into security priorities. The persistent instructions require confirmed fu...

Products Security
Products Security

Databricks makes user-scoped app authorization generally available

Databricks made on-behalf-of-user authorization generally available for apps that access supported platform APIs. Apps can now act with a signed-in user's identity, letting Unity Catalog enforce existing data permissions, row filt...

Security AI
Security AI

Cloudflare opens early beta of AI-assisted security investigations

Cloudflare says an early beta of its multi-agent investigation system is available in Managed Defense for eligible application-security alerts and cases. The system assembles evidence, links related alerts and recommends next step...