Ubiquiti has released patches for three maximum-severity flaws affecting UniFi Protect, UniFi OS, and UniFi Talk that could let remote attackers bypass authentication or trigger command injection without privileges. The company also fixed 18 more critical issues across its product line, including systems that have previously been targeted by botnets and active exploitation campaigns. #Ubiquiti #UniFiProtect #UniFiOS #UniFiTalk #CVE-2026-77537 #CVE-2026-77550 #CVE-2026-77554
Keypoints
- Ubiquiti patched three maximum-severity vulnerabilities in its UniFi products.
- CVE-2026-77537 affects UniFi Protect Application through improper input validation.
- CVE-2026-77550 can allow CRLF injection to bypass authentication on UniFi OS devices.
- CVE-2026-77554 is a command injection flaw in the UniFi Talk Application.
- Ubiquiti also fixed 18 additional critical issues across routers, gateways, NAS, and surveillance systems.