Censys now tracks more than 100,000 UniFi OS instances exposed online — a scale that sharpens the urgency of Ubiquiti’s latest security bulletin.
Three maximum-severity vulnerabilities and how they work
Ubiquiti has released patches addressing three maximum-severity vulnerabilities that attackers can exploit remotely without privileges. The company identified
- a weakness in the UniFi Protect Application video surveillance management platform;
- a CRLF injection flaw, tracked as CVE-2026-77550, that "a malicious actor with access to the network could exploit ... to bypass authentication" on UniFi OS devices or instances; and
- a command injection vulnerability, CVE-2026-77554, in the UniFi Talk Application Voice over IP (VoIP) phone system that stems from improper input validation.
Ubiquiti said the flaws can be exploited in low-complexity attacks that do not require user interaction and that threat actors can trigger them remotely without privileges.
Patched versions and the update footprint
The company said it addressed these flaws in UniFi Protect Application 7.2.105 or later, UniFi Talk Application 5.3.2 or later, and UniFi OS Server 5.1.21 and earlier. Administrators running affected builds should treat those version strings as the technical markers Ubiquiti provided for identifying patched and vulnerable software.

Your scanner finds 4,000 vulns. Which 12 matter?
Nubivance is a Rapid7 Registered Partner delivering vulnerability management as a service - scanning, risk-based prioritization, and remediation follow-through across IT and OT.
Fix the backlogExposure, past targeting, and exploit potential
Visibility data and prior incidents in the Ubiquiti ecosystem provide context for the risk. Censys now tracks more than 100,000 UniFi OS instances exposed online, though Censys warns that its data may include honeypots and historical scan results that do not necessarily reflect current, unpatched systems.
Ubiquiti has not disclosed whether any of the three maximum-severity flaws were exploited in the wild prior to this patching. Independent firms and law-enforcement actions cited in the company’s advisory underline a history of adversaries using Ubiquiti devices as part of larger operations: state-backed hacking groups and cybercriminals have targeted the vendor's products to build large botnets that helped conceal malicious activity, and in February 2024 the FBI dismantled Moobot, a botnet of Ubiquiti Edge OS routers used by the Russian Main Intelligence Directorate of the General Staff (GRU) to proxy malicious traffic in cyberespionage attacks.
Security researchers have also demonstrated the practical consequences of chaining such flaws: cybersecurity firm Bishop Fox showed that related vulnerabilities could be chained to achieve remote code execution with elevated privileges.
What this means for technologists, affected enterprises, and adversaries
- Technologists and security teams: The three issues are exploitable remotely without credentials and are described as low-complexity and non-interactive — factors that increase urgency. Teams should prioritize inventories that map UniFi Protect, UniFi Talk, and UniFi OS Server instances to the specific version strings Ubiquiti published and apply the stated updates.
- Affected enterprises and procurement leaders: Public scan data showing over 100,000 exposed UniFi OS instances highlights the need to verify whether externally reachable devices are intended to be internet-facing and whether compensating controls (network segmentation, perimeter filtering) are in place. Buyers and ops teams should also note that Censys results may include historical or decoy systems and therefore require local verification.
- Adversaries and threat actors: The combination of remote, no-privilege exploitation and past use of Ubiquiti devices in large-scale botnets creates incentive for threat actors to seek vulnerable systems. Bishop Fox’s chaining demonstration underscores that individual flaws can escalate when combined.
Where the record stands and why it matters
Ubiquiti patched an additional 18 critical-severity issues across a broad range of products on Thursday, extending the remediation work beyond these three maximum-severity flaws to include UniFi OS Server, UniFi Network Application, UniFi Protect AI Key, and many routers, gateways, NAS, and surveillance systems.
However, the company has yet to say whether the three new maximum-severity vulnerabilities were exploited in the wild before the patches were published. The Blue Report 2026 — which measures defenses technique by technique across 338 million simulations run in customer production environments — highlights a related operational point: "Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply." That observation is directly relevant here because vulnerabilities that allow initial access without user interaction can be the hinge point for follow-on actions that are harder to stop.
Ubiquiti’s published version markers and the existence of broad internet exposure create two immediate, concrete steps for defenders: confirm whether any UniFi OS, Protect, or Talk instances in their environments match the affected versions, and apply the listed updates. Beyond that, the unanswered question — how many Internet-exposed systems remain vulnerable and whether any were actively abused prior to patching — remains central to assessing the real-world impact of these fixes.




