Ubiquiti UniFi OS

Our sources currently list 11 known vulnerabilities affecting Ubiquiti UniFi OS. 6 are rated critical severity. 3 of 11 are actively exploited according to CISA, the most recent added 23 June 2026.

Last updated: 22 July 2026, 20:37 AEST

No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.

Known vulnerabilities in Ubiquiti UniFi OS, highest risk first.
CVESeverityExploitationPublishedSummary
CVE-2026-34910Critical (10.0)Actively exploitedA malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
CVE-2026-34908Critical (10.0)Actively exploitedA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
CVE-2026-34909Critical (10.0)Actively exploitedA malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulat…
CVE-2026-33000Critical (9.1)No exploitation reportedA malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
CVE-2026-54402Critical (9.9)No exploitation reportedA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the hos…
CVE-2026-34911High (7.7)No exploitation reportedA malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that…
CVE-2026-54403High (8.6)No exploitation reportedA malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS device…
CVE-2026-54404High (8.8)No exploitation reportedA malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges withi…
CVE-2023-31997Critical (9.0)No exploitation reportedUniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud Keys that are both (1) running…
CVE-2026-54401High (7.7)No exploitation reportedA malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances.
CVE-2026-55110High (7.5)No exploitation reportedA malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to trigger actions in …

Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.

Let's talk

3 of these are being actively exploited right now.

Our Newcastle team can audit your Ubiquiti estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.