“Three of the vulnerabilities had a Common Vulnerability Scoring System rating of 10 out of 10.”
The three highest-severity flaws: CVE-2026-77537, CVE-2026-77550, CVE-2026-77554
Ubiquiti disclosed Wednesday that three vulnerabilities in its UniFi product line received the maximum CVSS score of 10.0: CVE-2026-77537, CVE-2026-77550 and CVE-2026-77554. According to the company’s security bulletin, each of these three would allow a hacker to gain privileges on the affected device or application. In every case, the point of failure is described as an improper access control vulnerability — the same underlying problem present in seven of the total vulnerabilities Ubiquiti disclosed that day.
Scale of the release: 22 vulnerabilities, 21 rated critical
Ubiquiti’s bulletin listed 22 vulnerabilities in total. Of those, the company rated 21 as critical and one as high. All but one of the 22 vulnerabilities affect the UniFi line of products. Beyond the three 10.0-rated CVEs, other flaws in the disclosure would permit attackers to bypass authentication or run arbitrary commands, according to the bulletin’s descriptions.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildCompany response and prior disclosures
Ubiquiti released the bulletin with no additional commentary beyond the identification of the vulnerabilities and recommended mitigations. The company did not immediately respond to a request for comment about whether it had observed exploits in the wild prior to patching. The three maximum-severity fixes brought the company’s tally of 10.0 disclosures for the year to four: Ubiquiti had previously disclosed one 10.0-rated vulnerability in March, and one more in both May and July.
CISA’s earlier action and the broader context
Two months before Ubiquiti’s bulletin, the Cybersecurity and Infrastructure Security Agency added three Ubiquiti vulnerabilities to its list of flaws that were known to have been exploited, sometimes called the agency’s “must-patch” list. That administrative action signaled prior operational concern about Ubiquiti product vulnerabilities, and it precedes the set of disclosures Ubiquiti published Wednesday.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: The bulletin identifies multiple high-severity issues — including three CVSS 10.0 flaws that enable privilege escalation via improper access control — and recommends mitigations. Teams responsible for UniFi gear must prioritize applying the vendor’s patches or mitigations to eliminate avenues for privilege takeover, authentication bypass, and arbitrary command execution.
- Procurement and IT leadership: The bulletin underscores the exposure inherent in widely deployed networking products; Ubiquiti reported revenues of $2.57 billion last year, a fact that highlights the company’s broad market footprint and why patching is operationally urgent for many organizations.
- End users and small IT operators: Nearly the entire set of disclosed flaws affects the UniFi line. Users running UniFi devices or controllers should follow Ubiquiti’s recommended mitigations in the bulletin and verify that devices show the updated firmware or software to avoid scenarios where attackers could gain elevated privileges.
Ubiquiti’s Wednesday disclosure catalogs a significant number of high- and critical-severity faults in a single product family, including three defects at the maximum CVSS rating that permit privilege acquisition via improper access control. The company published fixes and mitigations but offered no immediate public commentary on whether the flaws had been exploited before patching — a detail the record still leaves open.
Read the original CyberScoop reporting: https://cyberscoop.com/ubiquiti-unifi-critical-vulnerabilities-patched/




