Ubiquiti Patches Three Max-Severity Vulnerabilities Allowing Unauthenticated Remote Exploits
Ubiquiti has released critical security patches for three maximum-severity vulnerabilities impacting its UniFi Protect, UniFi Talk, and UniFi OS platforms. These flaws could allow unauthenticated remote attackers to compromise devices, bypass authentication, or achieve command injection with low complexity and no user interaction.
Ubiquiti has issued urgent security patches to address three critical vulnerabilities that pose a significant risk to its **UniFi Protect**, **UniFi Talk**, and **UniFi OS** systems. These flaws, all rated maximum severity, can be exploited remotely without requiring any prior authentication.
### Unauthenticated Compromise in UniFi Protect
The first vulnerability, tracked as **CVE-2026-77537**, affects the **UniFi Protect Application** video surveillance management platform. It stems from an improper input validation weakness, enabling unauthenticated attackers to compromise unpatched devices remotely.
### Authentication Bypass via CRLF Injection
**Ubiquiti** also addressed **CVE-2026-77550**, a CRLF injection flaw that could allow remote, unprivileged attackers to bypass authentication on **UniFi OS** devices or instances. The company explained, "A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running CRLF Injection to bypass authentication to such UniFi OS devices or instances."
### Command Injection in UniFi Talk
The third maximum-severity vulnerability, **CVE-2026-77554**, is a command injection flaw found in the **UniFi Talk Application** Voice over IP (VoIP) phone system. This vulnerability also arises from improper input validation.
### Patch Information and Impact
These critical flaws have been addressed in **UniFi Protect Application 7.2.105** or later, **UniFi Talk Application 5.3.2** or later, and **UniFi OS Server 5.1.21** and earlier. While Ubiquiti has not confirmed in-the-wild exploitation for these specific vulnerabilities, they emphasize that the attacks are of low complexity and do not require user interaction.
### Broader Security Concerns for Ubiquiti Products
This release follows a recent wave of patches; just last Thursday, Ubiquiti patched 18 additional critical-severity issues across a wide range of products, including the **UniFi Network Application**, **UniFi Protect AI Key**, and various routers, gateways, NAS, and surveillance systems.
Threat intelligence firm **Censys** currently tracks over 100,000 **UniFi OS** instances exposed online. While this data may include historical scans and honeypots, it highlights the broad attack surface presented by Ubiquiti devices.

Ubiquiti products have frequently been targeted by both state-backed hacking groups and cybercriminals. In February 2024, the **FBI** disrupted **Moobot**, a botnet leveraging **Ubiquiti Edge OS** routers, which was used by the **Russian Main Intelligence Directorate of the General Staff (GRU)** to proxy malicious traffic for cyberespionage.
More recently, in June, **CISA** mandated federal agencies secure their systems within three days against three other max-severity **UniFi OS** vulnerabilities that were actively being exploited in the wild, demonstrating the real-world threat these flaws pose. Cybersecurity firm **Bishop Fox** later showed how these specific flaws could be chained to achieve remote code execution with elevated privileges.