Affected Systems
Ubiquiti UniFi Protect Application (fixed in 7.2.105+), UniFi Talk Application (fixed in 5.3.2+), and UniFi OS Server (5.1.21 and earlier). Over 100,000 UniFi OS instances exposed online. CVE-2026-77537 (input validation in Protect), CVE-2026-77550 (CRLF injection in OS), CVE-2026-77554 (command injection in Talk).
Exploitation Status
No confirmed exploitation disclosed by vendor. Low-complexity attacks requiring no user interaction. History of active targeting: CISA mandated patching of similar UniFi OS flaws in June after active exploitation; FBI disrupted GRU botnet using Ubiquiti routers in 2024.
Business Impact
Unauthenticated remote attackers can compromise video surveillance, VoIP, and network management infrastructure. Devices frequently targeted for botnet recruitment and traffic proxying in espionage campaigns. Large Internet-exposed attack surface (100k+ instances per Censys). 18 additional critical flaws patched same week across routers, gateways, NAS, and surveillance systems.
Urgency
🔴 Immediate
Recommended Actions
- Update UniFi Protect Application to version 7.2.105 or later immediately
- Update UniFi Talk Application to version 5.3.2 or later immediately
- Update UniFi OS Server to version 5.1.22 or later (versions 5.1.21 and earlier vulnerable)
- Audit network exposure of all UniFi devices and remove from direct Internet access where possible; place behind VPN or firewall with strict access control
- Review authentication logs on UniFi OS devices for anomalous access patterns or CRLF injection attempts (CVE-2026-77550)
- Inventory and patch 18 additional critical vulnerabilities disclosed August 26 across UniFi routers, gateways, NAS, and AI Key appliances
