Skip to content

// #cve-2026-34909

1 article

🌐 Network

Ubiquiti UniFi OS Security Bulletin 064: Three CVSS 10.0 Vulnerabilities Enable Unauthenticated Full Device Compromise

Ubiquiti published Security Bulletin 064 on 22 May disclosing five CVEs in UniFi OS devices, three of which score CVSS 10.0: an improper access control flaw, a path traversal enabling arbitrary file read and write, and a command injection that provides root shell access — all exploitable without authentication from the network. Enterprise environments using UniFi Wi-Fi infrastructure must update immediately.

#ubiquiti +8