Ubiquiti disclosed seven critical vulnerabilities across its UniFi product line in early July 2026, including a maximum-severity flaw (CVSS 10.0) that allows unauthenticated network attackers to execute arbitrary operating system commands on the UniFi Connect Application. With approximately 100,000 UniFi OS endpoints publicly accessible on the internet, the attack surface is substantial — and prior vulnerabilities in the UniFi product family have already attracted exploitation by Mirai-based botnets, establishing attacker tooling and target lists for this ecosystem.

The seven flaws affect widely deployed UniFi hardware and software used across enterprise networks, hotels, universities, and small-to-medium businesses worldwide. Ubiquiti has released patches and is urging immediate updates. The combination of unauthenticated access, OS-level command execution, and the prevalence of internet-facing UniFi deployments makes this a priority disclosure for any organization running Ubiquiti infrastructure — particularly those with distributed deployments managed by small IT teams.

Source: AboutDFIR | CyberRecaps

Commentary: CVSS 10.0 with unauthenticated RCE and 100,000 publicly exposed endpoints is the kind of disclosure that should trigger emergency patching procedures. UniFi is pervasive in exactly the environments that are hardest to patch quickly: small IT teams, distributed campuses, remote offices. The fact that prior UniFi vulnerabilities attracted Mirai botnet exploitation means attackers already have targeting infrastructure for this product family and will move fast.

For red teamers, this belongs at the top of external reconnaissance checklists immediately — unauthenticated RCE on network management infrastructure typically provides a pivot point for deeper lateral movement. For defenders: if your organization runs any publicly accessible UniFi endpoints, patch now and audit for any signs of prior exploitation given the Mirai precedent.

By Allan