Ubiquiti Unifi Critical Update

Security Advisory Bulletin 064

33.24K views

1 replies

Edited4 hours ago

Activity4 hours ago

Overview

Published: May 21, 2026

Updated: May 22, 2026

Version: 1.1

Revision: 1.1

Summary 1 of 5

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

Affected Products:

UniFi OS Server (Version 5.0.6 and earlier)

Mitigation:

Update your UniFi OS Server to Version 5.0.8 or later

Impact:

CVSS v3.0 Severity and Metrics:

Base Score: 9.1 Critical

Vector: 

CVSS: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CVE: CVE-2026-33000 (V3rlust)

Summary 2 of 5

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

Affected Products:

UCG-Industrial (Version 5.0.13 and earlier)

UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber (Version 5.0.16 and earlier)

UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise (Version 5.0.17 and earlier)

UniFi OS Server (Version 5.0.6 and earlier)

UNVR-G2 and UNVR-G2-Pro (Version 5.1.11 and earlier)

UDM-Beast, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 (Version 5.1.8 and earlier)

Mitigation:

Update your UCG-Industrial to Version 5.1.12 or later.

Update your UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber to Version 5.1.12 or later.

Update your UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise to Version 5.1.12 or later.

Update your UniFi OS Server to Version 5.0.8 or later.

Update your UNVR-G2 and UNVR-G2-Pro to Version 5.1.12 or later.

Update your UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 to Version 5.1.10 or later.

Update your UDM-Beast 5.1.11 or later.

Impact:

CVSS v3.0 Severity and Metrics:

Base Score: 10.0 Critical

Vector: 

CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE: CVE-2026-34908 (Duc Anh Nguyen (@heckintosh_))

Summary 3 of 5

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

Affected Products:

UCG-Industrial (Version 5.0.13 and earlier)

UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber (Version 5.0.16 and earlier)

UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise (Version 5.0.17 and earlier)

UniFi OS Server (Version 5.0.6 and earlier)

UNVR-G2 and UNVR-G2-Pro (Version 5.1.11 and earlier)

UDM-Beast, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 (Version 5.1.8 and earlier)

Express (Version 4.0.13 and earlier)

Mitigation:

Update your UCG-Industrial to Version 5.1.12 or later.

Update your UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber to Version 5.1.12 or later.

Update your UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise to Version 5.1.12 or later.

Update your UniFi OS Server to Version 5.0.8 or later.

Update your UNVR-G2 and UNVR-G2-Pro to Version 5.1.12 or later.

Update your UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 to Version 5.1.10 or later.

Update your UDM-Beast 5.1.11 or later.

Update your Express to Version 4.0.14 or later.

Impact:

CVSS v3.0 Severity and Metrics:

Base Score: 10.0 Critical

Vector: 

CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE: CVE-2026-34909 (Abdulaziz Almadhi | Catchify Security)

Summary 4 of 5

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

Affected Products:

UCG-Industrial (Version 5.0.13 and earlier)

UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber (Version 5.0.16 and earlier)

UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise (Version 5.0.17 and earlier)

UniFi OS Server (Version 5.0.6 and earlier)

UNVR-G2 and UNVR-G2-Pro (Version 5.1.11 and earlier)

UDM-Beast, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 (Version 5.1.8 and earlier)

Mitigation:

Update your UCG-Industrial to Version 5.1.12 or later.

Update your UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber to Version 5.1.12 or later.

Update your UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise to Version 5.1.12 or later.

Update your UniFi OS Server to Version 5.0.8 or later.

Update your UNVR-G2 and UNVR-G2-Pro to Version 5.1.12 or later.

Update your UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 to Version 5.1.10 or later.

Update your UDM-Beast 5.1.11 or later.

Impact:

CVSS v3.0 Severity and Metrics:

Base Score: 10.0 Critical

Vector: 

CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE: CVE-2026-34910 (John Carroll)

Summary 5 of 5

A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information.

Affected Products:

UCG-Industrial (Version 5.0.13 and earlier)

UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber (Version 5.0.16 and earlier)

UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise (Version 5.0.17 and earlier)

UniFi OS Server (Version 5.0.6 and earlier)

UNVR-G2 and UNVR-G2-Pro (Version 5.1.11 and earlier)

UDM-Beast, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 (Version 5.1.8 and earlier)

Mitigation:

Update your UCG-Industrial to Version 5.1.12 or later.

Update your UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber to Version 5.1.12 or later.

Update your UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise to Version 5.1.12 or later.

Update your UniFi OS Server to Version 5.0.8 or later.

Update your UNVR-G2 and UNVR-G2-Pro to Version 5.1.12 or later.

Update your UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 to Version 5.1.10 or later.

Update your UDM-Beast 5.1.11 or later.

Impact:

CVSS v3.0 Severity and Metrics:

Base Score: 7.7 High

Vector: 

CVSS: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CVE: CVE-2026-34911 (Hakai Security)

Share this post: