Ubiquiti has released updates to rectify several critical vulnerabilities identified in its UniFi OS software suite. The security flaws affect various applications, including UniFi Connect, Talk, Access, and Protect, and expose systems to potential command injection and privilege escalation attacks.
Among the vulnerabilities, CVE-2026-50746 is the most critical, allowing attackers with network access to execute command injections. It affects UniFi Connect Application versions up to 3.4.16 and is patched in version 3.4.20. Other vulnerabilities target UniFi Talk, Access, and Protect applications, posing risks to unauthorized access and control.
Ubiquiti's prompt advisory emphasizes the necessity for users to update their systems immediately. With the potential for these vulnerabilities to be exploited, timely updates are crucial for maintaining security and protecting networks from unauthorized interventions.
The updates address vulnerabilities with CVSS scores ranging from 9.1 to 10.0, denoting high severity. Each affected application has a specific updated version that users should apply to mitigate risks, underscoring the importance of staying up-to-date with security patches.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Ubiquiti has released updates to address several critical vulnerabilities in UniFi Connect, Talk, Access, Protect, and OS. These flaws, which include command injection and privilege escalation risks, could be exploited by attackers on the network, necessitating prompt user action to mitigate potential breaches.
Ubiquiti has released patches for seven critical vulnerabilities in UniFi OS, including CVE-2026-50746, which allows for command injection attacks on the UniFi Connect Application. Users are advised to update to version 3.4.20 or later to protect against potential exploits, which could affect numerous devices due to their online exposure.