Skip to content
You can now search across every topic, entity and event.What's new
Ubiquiti
OrganisationUS

Ubiquiti

US networking vendor whose UniFi line serves millions of SME and prosumer estates worldwide.

Ubiquiti is the US networking vendor whose UniFi OS Server shipped three CVSS-10 flaws that Bishop Fox chained into unauthenticated root, fixed in version 5.0.8 by 23 June 2026.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

How many businesses need to patch UniFi OS Server and how fast?

Timeline for Ubiquiti

#12 28 Jul

Mentioned in: KEV patch clocks fell to three days

Cybersecurity: Threats and Defences
#9 4 Jul

BOD 26-04, a fortnight of triage

Cybersecurity: Threats and Defences
#8 23 Jun

Patched all three CVSS-10 flaws in UniFi OS Server 5.0.8

Cybersecurity: Threats and Defences: Triple CVSS-10 Ubiquiti chain hits root
View full timeline →

Background

Ubiquiti is a US networking equipment vendor whose UniFi product line, including Dream Machine and Cloud Key appliances, serves millions of small business and prosumer network deployments worldwide. UniFi OS Server is Ubiquiti's own management layer, the software that configures, updates and remotely administers those Dream Machine and Cloud Key appliances from a single console.

The company's customer base skews toward smaller organisations and managed service providers rather than large enterprises with dedicated security operations, which shapes how quickly its user base can respond when a critical flaw surfaces.

The UniFi line spans routers, switches, WiFi access points and security cameras, unified under a single management interface intended to lower the technical bar for network administration. That accessibility has driven wide adoption but also means security-critical updates depend heavily on individual administrators applying patches promptly, rather than on dedicated IT teams.

Key Issues
UniFi root exploit

Ubiquiti patched three critical flaws fast

Bishop Fox disclosed on 23 June 2026 that three flaws in Ubiquiti's UniFi OS Server, all scored CVSS 10.0, could be chained into a working unauthenticated-root exploit. Ubiquiti had already shipped the fix in UniFi OS Server 5.0.8 by the time the research went public, and CISA still added all three to its KEV catalogue that day with a three-day remediation deadline.

The episode sits awkwardly for Ubiquiti: its patch was ready, but the device base is enormous and concentrated among small businesses and managed service providers, where a three-day window under CISA's new BOD 26-04 tiering is rarely achievable even with a fix already available.

Common Questions
Is Ubiquiti UniFi safe to use after the June 2026 vulnerabilities?
Yes, if updated. Ubiquiti patched all three CVSS 10.0 flaws (CVE-2026-34908/34909/34910) in UniFi OS Server 5.0.8. Administrators running any earlier version should treat the device as potentially compromised and update immediately.Source: Bishop Fox advisory / Ubiquiti release notes, 23 June 2026
What version of UniFi OS Server fixed the Bishop Fox vulnerabilities?
UniFi OS Server 5.0.8 patches all three CVSS 10.0 flaws: CVE-2026-34908 (access-control bypass), CVE-2026-34909 (PATH traversal), and CVE-2026-34910 (command injection).Source: Ubiquiti release notes, June 2026
Why did CISA add Ubiquiti flaws to the KEV catalogue?
CISA listed CVE-2026-34908/34909/34910 on 23 June 2026 because a public working exploit demonstrating unauthenticated root access was already available, and the product's wide deployment on business networks made the risk systemic. These were also the first entries under BOD 26-04's top 3-day patch tier.Source: CISA KEV catalogue, 23 June 2026
How widely deployed is Ubiquiti UniFi in businesses?
Ubiquiti's UniFi line is one of the most widely deployed networking platforms in the SME and prosumer segments globally, chosen for enterprise-grade capability at consumer-adjacent pricing. Exact installation figures are not published.Source: event
Source Material