Ubiquiti patches three maximum-severity UniFi flaws affecting Protect, UniFi OS, and Talk

Ubiquiti released fixes for three critical bugs that could let attackers break into some UniFi systems over the network without needing an account. The flaws are CVE-2026-77537 in UniFi Protect Application, CVE-2026-77550 in UniFi OS, and CVE-2026-77554 in UniFi Talk Application; Ubiquiti says the issues can be exploited in low-complexity attacks with no user interaction. Fixes are in UniFi Protect 7.2.105+, UniFi Talk 5.3.2+, and affected UniFi OS Server versions beyond 5.1.21.
Why it matters: Organizations and users running exposed UniFi surveillance, management, or VoIP systems could be remotely compromised or have authentication bypassed, so patching should be treated as urgent. Internet-facing UniFi deployments are especially at risk and should be updated and checked for exposure.

Sources

Ubiquiti patches three max severity security vulnerabilities
Sergiu Gatlan 2026.08.26 100% relevant
This article establishes a distinct new patch event covering three newly disclosed CVEs (CVE-2026-77537, CVE-2026-77550, CVE-2026-77554), not the previously tracked June or earlier UniFi flaw disclosures.
← Back to all stories