Skip to content
You can now search across every topic, entity and event.What's new
Bishop Fox
OrganisationUS

Bishop Fox

Bishop Fox is a US offensive security and penetration testing firm that published the public unauthenticated-root exploit chain against Ubiquiti UniFi OS Server in June 2026.

Bishop Fox is a US offensive-security firm that chained three CVSS-10 flaws in Ubiquiti's UniFi OS Server into a public unauthenticated-root exploit on 23 June 2026.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

How did Bishop Fox chain three CVSS-10 Ubiquiti flaws into unauthenticated root?

Timeline for Bishop Fox

#12 28 Jul

Mentioned in: KEV patch clocks fell to three days

Cybersecurity: Threats and Defences
#8 23 Jun

Chained CVE-2026-34908/34909/34910 into unauthenticated-root demo and published detection script

Cybersecurity: Threats and Defences: Triple CVSS-10 Ubiquiti chain hits root
View full timeline →

Background

Bishop Fox is a US offensive-security and penetration-testing firm founded in 2005 and headquartered in Phoenix, Arizona. It works across attack-surface management, red-team operations and adversarial research, with a client base concentrated in enterprise and government.

The firm's research model publishes working exploit chains against commercially deployed products rather than advisories alone, often paired with a detection script so defenders can act immediately. That approach puts direct pressure on vendors to patch quickly, at the cost of giving attackers a working blueprint on day one.

The Ubiquiti chain, three independent CVSS 10.0 flaws combined into unauthenticated root, is one of the more consequential examples of that model, given how widely UniFi OS Server is deployed among small businesses and managed service providers.

Key Issues
Ubiquiti exploit chain

Bishop Fox chained three CVSS-10 flaws

Bishop Fox published its research into Ubiquiti's UniFi OS Server on 23 June 2026, chaining an access-control bypass, a PATH traversal and a command injection, each scored CVSS 10.0, into a working demo that reaches root with no login required. It released a detection script the same day, so defenders could check for exposed devices as soon as the exploit went public.

CISA added all three flaws to its KEV catalogue that day under BOD 26-04's new three-day top tier, the first live use of that window. Bishop Fox's disclosure model, publishing working exploits alongside detection tooling rather than an advisory alone, is more aggressive than most vendors face and is credited with forcing Ubiquiti's fix into UniFi OS Server 5.0.8 within days.

Common Questions
What is Bishop Fox and what do they do?
Bishop Fox is a US offensive-security firm founded in 2005, specialising in penetration testing, red-team operations, and adversarial research. It publishes vulnerability research against deployed commercial products alongside detection scripts to help defenders act quickly.Source: Bishop Fox official website
What Ubiquiti vulnerability did Bishop Fox discover?
Bishop Fox chained three CVSS 10.0 flaws in Ubiquiti UniFi OS Server — CVE-2026-34908 (access-control bypass), CVE-2026-34909 (PATH traversal), and CVE-2026-34910 (command injection) — into a demo that achieves unauthenticated root. The chain was published on 23 June 2026 with a detection script; Ubiquiti fixed it in version 5.0.8.Source: Bishop Fox Ubiquiti research, June 2026
Why did Bishop Fox publish a working exploit for the Ubiquiti flaw?
Bishop Fox's responsible-disclosure policy includes releasing proof-of-concept code and detection scripts alongside disclosures. The aim is to compress the window between public knowledge and defender response: if the exploit is public, defenders can verify exposure the same day rather than waiting for the next scan cycle.Source: Bishop Fox disclosure methodology
How quickly did CISA respond to the Bishop Fox Ubiquiti disclosure?
CISA added all three CVEs to the KEV catalogue on 23 June 2026 with a 26 June Deadline, the first KEV batch scored under BOD 26-04's new top 3-day tier. The Deadline fell within days of the public exploit release.Source: CISA KEV catalogue, June 2026
Source Material