Ubiquiti has released emergency security updates to patch seven critical vulnerabilities in its UniFi OS ecosystem, including a maximum-severity flaw (CVE-2026-50746) that allows unauthenticated command injection via the UniFi Connect Application.
The vulnerabilities affect a wide range of Ubiquiti products — routers, gateways, NAS devices, surveillance systems, and the UniFi Connect, Talk, Access, and Protect applications — putting thousands of exposed instances at risk of full compromise.
Vulnerability Details
The most severe bug, CVE-2026-50746, carries a maximum severity rating and affects UniFi Connect Application versions 3.4.16 and earlier. UniFi Connect is a management software suite that Ubiquiti customers use to automate and manage commercial building operations — including smart LED lighting systems and electric vehicle chargers — through a single interface.
| Field | Value |
|---|---|
| CVE ID | CVE-2026-50746 |
| Severity | Max (Critical) |
| Type | Improper Access Control + Command Injection |
| Affected Product | UniFi Connect App (versions 3.4.16 and earlier) |
| Attack Vector | Network access, no authentication required |
| Fixed Version | UniFi Connect App 3.4.20 |
According to Ubiquiti: "A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device."
In addition to CVE-2026-50746, Ubiquiti patched six more critical-severity vulnerabilities:
- CVE-2026-50747 — UniFi Talk application
- CVE-2026-50748 — UniFi Access application
- CVE-2026-54400 — UniFi Protect application
- CVE-2026-54402 — UniFi OS Server
- CVE-2026-55115 — Routers and gateways
- CVE-2026-55116 — NAS and surveillance systems
Six of these seven vulnerabilities can be exploited in low-complexity attacks that do not require user interaction. Ubiquiti has not disclosed whether any of these flaws were exploited in the wild before the patches were released.
Impact Assessment
Threat intelligence company Censys tracks over 100,000 UniFi OS instances exposed online, with nearly 50,000 IP addresses in the United States alone. This large attack surface makes Ubiquiti devices a prime target for botnet operators and state-sponsored threat groups.
What attackers can achieve:
- Remote code execution on affected devices via command injection
- Privilege escalation — Bishop Fox demonstrated that similar UniFi OS flaws can achieve RCE with elevated privileges
- Botnet recruitment — Ubiquiti devices have historically been hijacked to build botnets that proxy malicious traffic
Historical Context
State-sponsored threat groups have repeatedly targeted Ubiquiti products. In February 2024, the FBI dismantled Moobot, a botnet of Ubiquiti Edge OS routers used by Russia's GRU to proxy malicious traffic in cyberespionage attacks.
In June 2026, CISA warned that hackers were actively exploiting three max-severity UniFi OS flaws that had been patched one month earlier, mandating that federal agencies secure their systems within three days. Bishop Fox later released a free detection script to help defenders discover vulnerable instances in their environments.
Affected Systems
The vulnerabilities span Ubiquiti's entire ecosystem:
- UniFi Connect Application — versions 3.4.16 and earlier
- UniFi Talk — affected versions
- UniFi Access — affected versions
- UniFi Protect — affected versions
- UniFi OS Server — affected versions
- Ubiquiti routers and gateways — affected firmware
- Ubiquiti NAS and surveillance systems — affected firmware
Mitigation and Patching
Ubiquiti has released patches for all affected products. Follow these steps immediately:
For UniFi Connect Application: Update to version 3.4.20 or later through the UniFi OS dashboard.
For other affected products: Apply the April security rollup patch or upgrade to the latest available version:
Cloud customers — patches were automatically applied to all RS/PRA cloud instances as of April 21, 2026.
Self-hosted customers — apply the security rollup patch manually if your instance is not subscribed to automatic updates.
Recommended:
- Restrict network access to UniFi OS management interfaces to trusted IPs only
- Disable remote management unless absolutely necessary
- Monitor Censys and Shodan for exposed instances on your network
- Check for unknown devices or unusual traffic patterns
Frequently Asked Questions
Are these vulnerabilities being exploited in the wild?
Ubiquiti has not confirmed active exploitation of these specific CVEs. However, given the publication of details and the availability of detection tools, exploitation is likely imminent.
Do I need to patch if I use UniFi cloud?
Cloud instances received automatic patches. Verify your instance is running the latest version from the UniFi dashboard.
How many Ubiquiti devices are exposed online?
Censys tracks over 100,000 UniFi OS instances publicly accessible online, with the largest concentration in the United States (nearly 50,000 IPs).
Are other Ubiquiti products affected?
Yes — the vulnerabilities span routers, gateways, NAS, surveillance, UniFi Connect, Talk, Access, and Protect applications. All UniFi OS deployments should be updated.
Key Takeaways
- Patch immediately if you self-host UniFi OS — 7 critical CVEs including a max-severity command injection.
- 100,000+ instances exposed online — Ubiquiti devices are a prime target for botnets.
- Low-complexity attacks — six of seven CVEs require no user interaction to exploit.
- Historical targeting — GRU and other state actors have weaponized Ubiquiti devices before.
- Check cloud instances — automatic patches were applied, but verify your version.
Sources:
- BleepingComputer — Ubiquiti warns of new max severity UniFi OS vulnerability
- Censys — Internet-exposed UniFi OS instances
- Ubiquiti Security Advisory — UniFi OS critical vulnerabilities
Automated Transmission
This entry was synthesized and populated dynamically using native API integrations.