CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0330 [1.00] [M/H] Kwetsbaarheden verholpen in UniFi-producten van Ubiquiti

unknownpublic exploitCVE-2026-77533CVE-2026-77534CVE-2026-77535CVE-2026-77536CVE-2026-77537CVE-2026-77538
Ubiquiti heeft kwetsbaarheden verholpen in verschillende UniFi-producten, waaronder UniFi Protect, UniFi OS, UniFi Network Application, UniFi Connect, UniFi Access Application, UniFi OS Server, UID Enterprise Agent, UniFi Connect Display Cast Pro, UniFi Enterprise Audio/Video Bridge en UniFi Talk. De kwetsbaarheden betreffen voornamelijk improper input validation en improper access control binnen de genoemde UniFi-producten. Door onvoldoende validatie van invoer kunnen kwaadwillenden met netwerktoegang, soms zonder verhoogde privileges en soms met verhoogde privileges, command injection uitvoeren op het hostapparaat. Dit maakt het mogelijk om willekeurige commando's uit te voeren met de rechten van het getroffen proces of de applicatie. Daarnaast bevatten sommige UniFi OS-apparaten een kwetsbaarheid waarbij improper neutralization van CRLF-sequenties kan leiden tot het omzeilen van authenticatiemechanismen, wat ongeautoriseerde toegang tot apparaatfuncties of beheerinterfaces mogelijk maakt. Verder is er een kwetsbaarheid met actieve debugcode in UniFi OS-apparaten die privilege-escalatie door een aanvaller met lage privileges op het netwerk mogelijk maakt. De kwetsbaarheden stellen een aanvaller in staat om privileges te escaleren, ongeautoriseerde acties uit te voeren en controle over de getroffen systemen te verkrijgen. Exploitatie vereist netwerktoegang, waarbij sommige kwetsbaarheden ook zonder verhoogde privileges kunnen worden misbruikt.

CSIRTS triage

What
Improper input validation and access control flaws enable command injection on host devices and CRLF-based authentication bypass.
Who is affected
UniFi Protect, UniFi OS, UniFi Network Application, UniFi Connect, UniFi Access Application, UniFi OS Server, UID Enterprise Agent, and related UniFi products with network access.
Urgency
High; command injection allows arbitrary code execution with application/process privileges; authentication bypass enables unauthorized access.
Action
Apply Ubiquiti security patches for affected UniFi product versions; validate network segmentation and authentication mechanisms post-patch.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch UniFi products

Get an email when a new UniFi products advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-08-27
Exploitation
Not in CISA KEV at last sync

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0330

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-77533coverage & exploitation statusNVD · CVE.org
CVE-2026-77534coverage & exploitation statusNVD · CVE.org
CVE-2026-77535coverage & exploitation statusNVD · CVE.org
CVE-2026-77536coverage & exploitation statusNVD · CVE.org
CVE-2026-77537coverage & exploitation statusNVD · CVE.org
CVE-2026-77538coverage & exploitation statusNVD · CVE.org
CVE-2026-77539coverage & exploitation statusNVD · CVE.org
CVE-2026-77540coverage & exploitation statusNVD · CVE.org
CVE-2026-77541coverage & exploitation statusNVD · CVE.org
CVE-2026-77542coverage & exploitation statusNVD · CVE.org
CVE-2026-77543coverage & exploitation statusNVD · CVE.org
CVE-2026-77545coverage & exploitation statusNVD · CVE.org
CVE-2026-77546coverage & exploitation statusNVD · CVE.org
CVE-2026-77547coverage & exploitation statusNVD · CVE.org
CVE-2026-77548coverage & exploitation statusNVD · CVE.org
CVE-2026-77549coverage & exploitation statusNVD · CVE.org
CVE-2026-77550coverage & exploitation statusNVD · CVE.org
CVE-2026-77551coverage & exploitation statusNVD · CVE.org
CVE-2026-77552coverage & exploitation statusNVD · CVE.org
CVE-2026-77553coverage & exploitation statusNVD · CVE.org
CVE-2026-77554coverage & exploitation statusNVD · CVE.org
CVE-2026-77557coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Kwetsbaarheden verholpen in

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories