Ubiquiti patches 25 critical UniFi vulnerabilities
Network equipment maker Ubiquiti warned that multiple critical flaws in its UniFi product line could allow attackers to take full control of devices remotely. The company released updates addressing 25 software vulnerabilities, seven of which are rated critical with CVSS scores ranging from 9.9 to a maximum of 10.0. The most severe issue (CVE‑2026‑50746) affects the UniFi Connect app and permits unauthenticated command execution on the host system. Other high‑severity bugs involve SQL injection in UniFi Talk (CVE‑2026‑50747), input‑validation errors in UniFi Access (CVE‑2026‑50748) and UniFi OS (CVE‑2026‑54402), and server‑side request forgery in UniFi Protect (CVE‑2026‑55115). The Dutch National Cyber Security Centre and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) have both issued alerts about the threats. Ubiquiti’s patches address the identified flaws across its routers, switches, access points, cameras and other networking devices, mitigating the risk of remote takeover and network compromise.