Summary

CISA has added three critical Ubiquiti UniFi OS vulnerabilities to its Known Exploited Vulnerabilities catalog, all carrying the maximum CVSS score of 10.0. The flaws — CVE-2026-34908 (access control bypass), CVE-2026-34909 (path traversal), and CVE-2026-34910 (command injection) — can be chained together to achieve full unauthenticated remote code execution with elevated privileges on affected devices.

Researchers at Bishop Fox demonstrated the complete exploit chain and released a free detection script. The vulnerabilities require no authentication, no user interaction, and can be exploited remotely against any internet-exposed UniFi OS instance. Federal agencies have been ordered to patch by June 26, 2026, under Binding Operational Directive 26-04.

Ubiquiti released security updates in May 2026, but active exploitation in the wild prompted CISA’s emergency addition to the KEV catalog on June 23. Organizations running UniFi OS should treat this as a hair-on-fire priority.

Source

Commentary

Three CVSS 10.0 vulnerabilities in a single product that chain into full RCE is about as bad as it gets. UniFi devices are everywhere — small businesses, home labs, enterprises — and many sit directly on the internet. The fact that Bishop Fox published a full exploitation walkthrough means this is trivially reproducible by anyone with curl and patience.

If you run UniFi OS and haven’t patched since May, drop everything and update. The CISA deadline is tomorrow, but the real deadline was the moment these started getting exploited in the wild.

By Allan