Ubiquiti released fixes for three critical bugs that could let attackers break into some UniFi systems over the network without needing an account. The flaws are CVE-2026-77537 in UniFi Protect Application, CVE-2026-77550 in UniFi OS, and CVE-2026-77554 in UniFi Talk Application; Ubiquiti says the issues can be exploited in low-complexity attacks with no user interaction. Fixes are in UniFi Protect 7.2.105+, UniFi Talk 5.3.2+, and affected UniFi OS Server versions beyond 5.1.21.
Why it matters: Organizations and users running exposed UniFi surveillance, management, or VoIP systems could be remotely compromised or have authentication bypassed, so patching should be treated as urgent. Internet-facing UniFi deployments are especially at risk and should be updated and checked for exposure.
Sergiu Gatlan
2026.08.26
100% relevant
This article establishes a distinct new patch event covering three newly disclosed CVEs (CVE-2026-77537, CVE-2026-77550, CVE-2026-77554), not the previously tracked June or earlier UniFi flaw disclosures.
← Back to all stories