NCSC-2026-0221 [1.00] [M/H] Vulnerabilities fixed in UniFi products from Ubiquiti Networks
Ubiquiti Networks has fixed vulnerabilities in various UniFi products, including UniFi Connect Application, UniFi Talk Application, UniFi Access Application, UniFi OS, UniFi Network Application, and UniFi Protect Application. The vulnerabilities affect multiple UniFi products and include command injection, SQL injection, improper input validation, improper access control, server-side request forgery (SSRF), path traversal, authentication bypass, and persistent privilege escalation. Attackers with network access, sometimes with limited privileges and sometimes after authentication, can execute arbitrary commands, escalate privileges, read or modify files, bypass authentication, and cause Denial of Service (DoS). Some vulnerabilities require user interaction, such as visiting a malicious website, while others can be exploited directly via network access. The vulnerabilities are present in applications and platforms used for network management, access control, video surveillance, and security monitoring within the UniFi product line.
CSIRTS triage
- What
- Various vulnerabilities in UniFi products allow attackers to execute arbitrary commands, escalate privileges, and cause denial of service.
- Who is affected
- Attackers with network access to UniFi products can exploit these vulnerabilities.
- Urgency
- Remediation is urgent due to the high potential for exploitation and impact.
- Action
- Update all affected UniFi products to the latest versions.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch UniFi products
Get an email when a new UniFi products advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0221
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-507462.5% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 83% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-507470.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-507481.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 66% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-544000.52% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-544010.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-544021.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 68% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-544030.62% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-544040.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-544050.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-544060.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] Ubiquiti UniFi: Multiple vulnerabilitiescert-bund
- highCVE-2026-56842: A malicious actor with access to the network and under certain conditions could exploit an Inc…nvd
- highCVE-2026-56841: A malicious actor with access to the network and low privileges could exploit an authenticated…nvd
- highCVE-2026-55119: A malicious actor with access to the network and low privileges could exploit an Improper Acce…nvd
- highCVE-2026-55118: A malicious actor with access to the network,low privileges and under certain conditions could…nvd
- highCVE-2026-55117: A malicious actor with access to the network could exploit a Path Traversal vulnerability foun…nvd
- criticalCVE-2026-55116: A malicious actor with access to the network and under certain network configurations could ex…nvd
- criticalCVE-2026-55115: A malicious actor with access to the network and low privileges could exploit a Server-Side Re…nvd
- highCVE-2026-55114: A malicious actor with access to the network and low privileges could exploit an Improper Acce…nvd
- highCVE-2026-55113: A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF…nvd
- highCVE-2026-55112: A malicious actor with access to the network and low privileges and under certain conditions c…nvd
- highCVE-2026-55111: A malicious actor with access to the network could exploit a Path Traversal vulnerability foun…nvd
Recent advisories for UniFi products from
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-71143: Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Comm…nvd · 2026-08-18
- highCVE-2026-71142: Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Comm…nvd · 2026-08-18
- highCVE-2026-60969: Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: …nvd · 2026-08-18
- highCVE-2026-60914: Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: …nvd · 2026-08-18
- mediumCVE-2026-60895: Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: …nvd · 2026-08-18
- highCVE-2026-60889: Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: …nvd · 2026-08-18
More from NCSC-NL Advisories
- unknownNCSC-2026-0316 [1.00] [M/H] Vulnerabilities resolved in Oracle PeopleSoft Enterprise2026-08-19
- unknownNCSC-2026-0315 [1.00] [M/H] Vulnerabilities resolved in Oracle MySQL2026-08-19
- unknownNCSC-2026-0314 [1.00] [M/H] Vulnerabilities resolved in Oracle Java SE2026-08-19
- unknownNCSC-2026-0313 [1.00] [M/H] Vulnerabilities resolved in Oracle Business Intelligence Enterprise Edition and Or…2026-08-19
- unknownNCSC-2026-0312 [1.00] [M/H] Vulnerabilities resolved in Oracle Financial Services2026-08-19