Ubiquiti Patches Critical UniFi OS Flaws Including Max Severity Vulnerability
Ubiquiti releases security updates to patch seven critical vulnerabilities in UniFi OS, including a maximum-severity flaw tracked as CVE-2026-50746. This vulnerability affects the UniFi Connect Application versions 3.4.16 and earlier, which customers use to manage commercial building operations such as smart LED lighting and electric vehicle chargers. A malicious actor with network access can exploit this improper access control weakness to execute command injection attacks on the host device.
Beyond the maximum-severity issue, Ubiquiti addresses six additional critical vulnerabilities across UniFi Talk, UniFi Access, UniFi Protect, UniFi OS Server, and various routers, gateways, NAS devices, and surveillance systems. Six of these flaws can be exploited through low-complexity attacks that require no user interaction. Ubiquiti does not disclose whether any of the vulnerabilities face active exploitation in the wild prior to patching.
Threat intelligence firm Censys identifies over 100,000 UniFi OS instances exposed online, with nearly 50,000 located in the United States. State-sponsored and cybercriminal groups frequently target Ubiquiti products, hijacking them to build botnets for concealing malicious activity. The FBI previously dismantled a Moobot botnet of Ubiquiti routers used by Russian intelligence for cyberespionage operations.