
Bishop Fox
Bishop Fox is a US offensive security and penetration testing firm that published the public unauthenticated-root exploit chain against Ubiquiti UniFi OS Server in June 2026.
Bishop Fox is a US offensive-security firm that chained three CVSS-10 flaws in Ubiquiti's UniFi OS Server into a public unauthenticated-root exploit on 23 June 2026.
Last refreshed: 3 August 2026 · Appears in 1 active topic
How did Bishop Fox chain three CVSS-10 Ubiquiti flaws into unauthenticated root?
Timeline for Bishop Fox
Mentioned in: KEV patch clocks fell to three days
Cybersecurity: Threats and DefencesChained CVE-2026-34908/34909/34910 into unauthenticated-root demo and published detection script
Cybersecurity: Threats and Defences: Triple CVSS-10 Ubiquiti chain hits rootBackground
Bishop Fox is a US offensive-security and penetration-testing firm founded in 2005 and headquartered in Phoenix, Arizona. It works across attack-surface management, red-team operations and adversarial research, with a client base concentrated in enterprise and government.
The firm's research model publishes working exploit chains against commercially deployed products rather than advisories alone, often paired with a detection script so defenders can act immediately. That approach puts direct pressure on vendors to patch quickly, at the cost of giving attackers a working blueprint on day one.
The Ubiquiti chain, three independent CVSS 10.0 flaws combined into unauthenticated root, is one of the more consequential examples of that model, given how widely UniFi OS Server is deployed among small businesses and managed service providers.
Bishop Fox chained three CVSS-10 flaws
Bishop Fox published its research into Ubiquiti's UniFi OS Server on 23 June 2026, chaining an access-control bypass, a PATH traversal and a command injection, each scored CVSS 10.0, into a working demo that reaches root with no login required. It released a detection script the same day, so defenders could check for exposed devices as soon as the exploit went public.
CISA added all three flaws to its KEV catalogue that day under BOD 26-04's new three-day top tier, the first live use of that window. Bishop Fox's disclosure model, publishing working exploits alongside detection tooling rather than an advisory alone, is more aggressive than most vendors face and is credited with forcing Ubiquiti's fix into UniFi OS Server 5.0.8 within days.