NCSC-2026-0330 [1.00] [M/H] Kwetsbaarheden verholpen in UniFi-producten van Ubiquiti
Ubiquiti heeft kwetsbaarheden verholpen in verschillende UniFi-producten, waaronder UniFi Protect, UniFi OS, UniFi Network Application, UniFi Connect, UniFi Access Application, UniFi OS Server, UID Enterprise Agent, UniFi Connect Display Cast Pro, UniFi Enterprise Audio/Video Bridge en UniFi Talk. De kwetsbaarheden betreffen voornamelijk improper input validation en improper access control binnen de genoemde UniFi-producten. Door onvoldoende validatie van invoer kunnen kwaadwillenden met netwerktoegang, soms zonder verhoogde privileges en soms met verhoogde privileges, command injection uitvoeren op het hostapparaat. Dit maakt het mogelijk om willekeurige commando's uit te voeren met de rechten van het getroffen proces of de applicatie. Daarnaast bevatten sommige UniFi OS-apparaten een kwetsbaarheid waarbij improper neutralization van CRLF-sequenties kan leiden tot het omzeilen van authenticatiemechanismen, wat ongeautoriseerde toegang tot apparaatfuncties of beheerinterfaces mogelijk maakt. Verder is er een kwetsbaarheid met actieve debugcode in UniFi OS-apparaten die privilege-escalatie door een aanvaller met lage privileges op het netwerk mogelijk maakt. De kwetsbaarheden stellen een aanvaller in staat om privileges te escaleren, ongeautoriseerde acties uit te voeren en controle over de getroffen systemen te verkrijgen. Exploitatie vereist netwerktoegang, waarbij sommige kwetsbaarheden ook zonder verhoogde privileges kunnen worden misbruikt.
CSIRTS triage
- What
- Improper input validation and access control flaws enable command injection on host devices and CRLF-based authentication bypass.
- Who is affected
- UniFi Protect, UniFi OS, UniFi Network Application, UniFi Connect, UniFi Access Application, UniFi OS Server, UID Enterprise Agent, and related UniFi products with network access.
- Urgency
- High; command injection allows arbitrary code execution with application/process privileges; authentication bypass enables unauthorized access.
- Action
- Apply Ubiquiti security patches for affected UniFi product versions; validate network segmentation and authentication mechanisms post-patch.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch UniFi products
Get an email when a new UniFi products advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0330
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-775331.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 61% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-775340.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-775350.81% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-775360.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-775370.94% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 58% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-775380.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-775390.81% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-775400.81% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-775410.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-775420.81% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Ubiquiti UnifiOS: Multiple vulnerabilitiescert-bund
- criticalCVE-2026-77557: A malicious actor with access to the network could exploit an Improper Access Control vulnerab…nvd
- criticalCVE-2026-77554: A malicious actor with access to the network could exploit an Improper Input Validation vulner…nvd
- criticalCVE-2026-77553: A malicious actor with access to the network and low privileges could exploit an Improper Acce…nvd
- criticalCVE-2026-77552: A malicious actor with access to the network could exploit an Improper Input Validation vulner…nvd
- criticalCVE-2026-77551: A malicious actor with access to the network and under certain conditions could exploit an Imp…nvd
- criticalCVE-2026-77550: A malicious actor with access to the network could exploit an Improper Neutralization of CRLF …nvd
- criticalCVE-2026-77549: A malicious actor with access to the network and under certain conditions could exploit an Imp…nvd
- criticalCVE-2026-77548: A malicious actor with access to the network and low privileges could exploit an Improper Inpu…nvd
- criticalCVE-2026-77547: A malicious actor with access to the network and low privileges could exploit an Improper Inpu…nvd
- criticalCVE-2026-77546: A malicious actor with access to the network and low privileges could exploit an Improper Inpu…nvd
- criticalCVE-2026-77545: A malicious actor with access to the network, low privileges and under certain conditions coul…nvd
Recent advisories for Kwetsbaarheden verholpen in
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN productenncsc-nl · 2026-09-10
- unknownNCSC-2026-0364 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Illustratorncsc-nl · 2026-09-09
- unknownNCSC-2026-0363 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Managerncsc-nl · 2026-09-09
- unknownNCSC-2026-0362 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusionncsc-nl · 2026-09-09
- unknownNCSC-2026-0361 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Commercencsc-nl · 2026-09-09
- unknownNCSC-2026-0360 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Photoshop Desktopncsc-nl · 2026-09-09
More from NCSC-NL Advisories
- unknownNCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN producten2026-09-10
- unknownNCSC-2026-0364 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Illustrator2026-09-09
- unknownNCSC-2026-0363 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Manager2026-09-09
- unknownNCSC-2026-0362 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusion2026-09-09
- unknownNCSC-2026-0361 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Commerce2026-09-09