Free delivery

GGuestNot signed in
You're not signed in
LoginCreate account

8/26/2026 • Security

Ubiquiti Patches 21 Critical Flaws Across the Whole UniFi Line

Ubiquiti's Security Advisory Bulletin 067 fixes 21 critical-severity flaws spanning UniFi Protect, Network, Access, Talk, Connect and OS — several exploitable with no login at all. Here's what's real, what's not, and what to do about it.

A heads-up, not a sales pitch

We keep an eye on advisories that touch the gear our customers actually run, and every so often one lands that's worth passing on for its own sake — not because we're chasing a sale. Ubiquiti's UniFi kit — Wi-Fi, switches, cameras, door access, even office phones — sits at the centre of a lot of small networks, including some we've helped set up. So when Ubiquiti quietly dropped its biggest advisory in months, it seemed worth a plain-English translation.

What happened, in plain English

On 26 August 2026, Ubiquiti published Security Advisory Bulletin 067, fixing 21 critical-severity vulnerabilities (CVSS base scores from 8.2 up to a perfect 10.0) spread across almost the entire UniFi product family: UniFi Protect (cameras/NVR), UniFi OS (the underlying platform on Dream Machines, Cloud Gateways and NAS devices), UniFi Network Application, UniFi Access (door controllers), UniFi Talk (VoIP), UniFi Connect, the UID Enterprise Agent, and a couple of smaller peripherals (Connect Display Cast Pro, the Enterprise Audio/Video Bridge, Protect AI Key).

Most of the bugs fall into two buckets, and the nuance matters:

  • Command injection / improper input validation — an attacker who can reach the device sends it a malformed request and gets it to run arbitrary commands. This covers the worst entries, including CVE-2026-77537 (UniFi Protect, CVSS 10.0) and CVE-2026-77554 (UniFi Talk, CVSS 10.0) — both confirmed via NVD as needing no privileges and no user interaction, just network reach. A related one, CVE-2026-77533 (also UniFi Protect, CVSS 9.9), is nearly as bad but does need low-level credentials first — worth knowing the difference before assuming every entry here is a walk-in.
  • CRLF header injection leading to authentication bypassCVE-2026-77550 (UniFi OS, CVSS 10.0, confirmed via NVD) lets a network attacker smuggle characters into an HTTP header to skip the login step entirely on affected UniFi OS devices and instances.

Ubiquiti has shipped fixes for all of it — UniFi Protect 7.2.105+, UniFi OS 5.1.31–5.1.37 depending on device, UniFi Network Application 10.5.67+, UniFi Access 4.3.5+, UniFi Talk 5.3.2+, UniFi Connect 3.24.22+, and current builds for the smaller peripherals. As of publication, none of these 21 has a confirmed public exploit or a CISA Known Exploited Vulnerabilities (KEV) listing — this is a proactive patch, not a "you've already been hit" alert. That's worth saying plainly, because it's tempting to round every CVSS-10.0 headline up to "actively exploited," and that's not accurate here.

Why it matters (the real lesson)

The individual bugs matter less than the shape of the disclosure. Twenty-one critical flaws in one release, touching cameras, door locks, phones, Wi-Fi and the core OS all at once, is a reminder of something easy to forget when a vendor's ecosystem is genuinely convenient to run: the more of your network one brand touches, the wider the blast radius when that brand has a bad week. UniFi's appeal is exactly that — one app, one login, one set of firmware to think about, for gear that used to mean five different vendor portals. That's a real advantage day-to-day. It also means a single advisory like this one can touch your cameras, your front-door lock and your office phones in the same afternoon.

The honest bit: no vendor is immune — including the ones we like

UniFi is popular gear for good reason, and we're not about to spin this into "Ubiquiti bad." Every serious vendor ships bugs; what separates the good ones is how fast and how completely they fix them, and Ubiquiti has form here — this isn't its first big bulletin of 2026. Earlier this year, three maximum-severity UniFi OS flaws (access-control bypass, path traversal and command injection) were confirmed as actively exploited and added to CISA's KEV catalogue, triggering a mandatory patch window for US federal agencies. That's the pattern worth remembering: this ecosystem has been a real target before, not just a hypothetical one.

Where Ubiquiti's platform genuinely helps here is the update path. UniFi OS devices enrolled with automatic updates turned on (via the UniFi console or Site Manager) get security fixes pushed without anyone needing to remember to log in — the same lifecycle advantage we've written about for cloud-managed firewalls. Self-hosted or offline controllers don't get that for free; someone still has to go and click "update." That's a genuine difference worth knowing, not a pitch.

What we'd suggest you actually do

No urgency for urgency's sake — just a sensible checklist:

  1. Take stock of what you're actually running. UniFi Protect cameras, a Dream Machine or Cloud Gateway, Access door controllers, Talk phones — list what's on your network and check its current firmware version against the fixed versions above.
  2. Update, don't defer. If auto-update is available and enabled, confirm it's actually applied (check the "last updated" timestamp in the console) rather than assuming it happened silently.
  3. If you self-host a UniFi controller, log in and update it manually — auto-update doesn't cover every deployment model.
  4. Don't expose management interfaces to the open internet. Several of these bugs only need network reach, not physical access — an internet-facing UniFi console is a much bigger target than one sitting behind a firewall or VPN.
  5. Cover the basics regardless of brand: unique admin credentials, MFA where the console supports it, and a habit of checking vendor advisories a few times a year rather than only when something breaks.

This is the same hygiene we flagged in our look at FortiBleed and patch timing — the fix existing isn't the finish line; applying it is.

The friendly takeaway

Twenty-one critical bugs in one bulletin sounds alarming, and the worst few genuinely are serious — but Ubiquiti has already shipped the fixes, nothing here is confirmed exploited yet, and the actual task for most businesses is a firmware check that takes a few minutes. That's the whole point of watching this stuff for you: so you get "here's what to check" instead of a scary headline with no next step.

If you'd ever like a second pair of eyes on your UniFi setup — or any gear at the edge of your network — no obligation, no hard sell. That's what we're here for.

References

Contact Us

Email: [email protected]

Phone: 1300 989 334

About

Your one-stop technology hub for all your networking, security, and IT needs. From cutting-edge networking solutions to robust security products, we provide everything your business requires to stay connected, secure, and efficient. Whether you're looking for advanced hardware, software, or services, we offer reliable, innovative technology tailored to help you build and protect your digital infrastructure.

Copyright © 2026 TYONLINE TECHNOLOGY PTY. LTD. All Rights Reserved.