< Back to all clusters
[TECHNOLOGY] · Germany, Brazil, United States · 4 sources

Critical Ubiquiti Device Vulnerabilities Exploited by Attackers

Three critical vulnerabilities in Ubiquiti networking equipment have been assigned CVSS scores of 10/10. The flaws—identified as CVE-2026-34908, CVE-2026-34909 and CVE-2026-34910—allow unauthenticated remote attackers to change system settings, access underlying accounts and inject commands. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that threat actors are actively targeting these weaknesses.

Ubiquiti released UniFi OS Server version 5.0.8 in May, which patches the three defects. Despite the fix, user reports indicate real‑world exploitation, including the creation of fraudulent admin accounts. Security teams are urged to verify whether vulnerable devices are present, restrict internet‑exposed management interfaces, and enable multi‑factor authentication where possible.