Advertisement

Three 10.0 security flaws fixed across Ubiquiti’s UniFi line

The communications product company disclosed 22 total Wednesday, all but one of which was rated “critical” at 9.0 or higher.
Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
The UniFi brand logo on March 5, 2026. (Photo by Joan Cros/NurPhoto via Getty Images)

Ubiquiti has patched 21 critical vulnerabilities, three of which were rated the highest severity possible, the communications product company said Wednesday in a security bulletin.

In all, the company patched 22 vulnerabilities, with the last one rated “high,” it said in the bulletin.

Three of the vulnerabilities had a Common Vulnerability Scoring System rating of 10 out of 10. Each of them would allow a hacker to access privileges on the device or application.

All but one of the 22 vulnerabilities affect the UniFi line of products. The three maximum-security vulnerabilities are CVE-2026-77537, CVE-2026-77550 and CVE-2026-77554.

Advertisement

In all three, hackers could exploit an improper access control vulnerability, the same kind in seven of the total vulnerabilities Ubiquiti disclosed Wednesday. Other vulnerabilities would allow hackers to do things like bypass authentication or run arbitrary commands.

Ubiquiti, which claimed revenues of $2.57 billion last year, released the bulletin without commentary, besides identifying the vulnerabilities and recommended mitigations. The company did not immediately respond to a request for comment about whether it had seen any of the exploits used in the wild before they were patched.

The trio of maximum-security vulnerabilities patched equals the total the company had disclosed this year before Wednesday.

In March, the company disclosed that it had patched a single maximum-security vulnerability. It disclosed one more in both May and July of this year.

Two months ago, the Cybersecurity and Infrastructure Security Agency added three Ubiquiti vulnerabilities to its list of flaws that were known to have been exploited, sometimes called the agency’s “must-patch” list.

Advertisement

Latest Podcasts