
Ubiquiti
US networking vendor whose UniFi line serves millions of SME and prosumer estates worldwide.
Ubiquiti is the US networking vendor whose UniFi OS Server shipped three CVSS-10 flaws that Bishop Fox chained into unauthenticated root, fixed in version 5.0.8 by 23 June 2026.
Last refreshed: 3 August 2026 · Appears in 1 active topic
How many businesses need to patch UniFi OS Server and how fast?
Timeline for Ubiquiti
Mentioned in: KEV patch clocks fell to three days
Cybersecurity: Threats and DefencesBOD 26-04, a fortnight of triage
Cybersecurity: Threats and DefencesPatched all three CVSS-10 flaws in UniFi OS Server 5.0.8
Cybersecurity: Threats and Defences: Triple CVSS-10 Ubiquiti chain hits rootBackground
Ubiquiti is a US networking equipment vendor whose UniFi product line, including Dream Machine and Cloud Key appliances, serves millions of small business and prosumer network deployments worldwide. UniFi OS Server is Ubiquiti's own management layer, the software that configures, updates and remotely administers those Dream Machine and Cloud Key appliances from a single console.
The company's customer base skews toward smaller organisations and managed service providers rather than large enterprises with dedicated security operations, which shapes how quickly its user base can respond when a critical flaw surfaces.
The UniFi line spans routers, switches, WiFi access points and security cameras, unified under a single management interface intended to lower the technical bar for network administration. That accessibility has driven wide adoption but also means security-critical updates depend heavily on individual administrators applying patches promptly, rather than on dedicated IT teams.
Ubiquiti patched three critical flaws fast
Bishop Fox disclosed on 23 June 2026 that three flaws in Ubiquiti's UniFi OS Server, all scored CVSS 10.0, could be chained into a working unauthenticated-root exploit. Ubiquiti had already shipped the fix in UniFi OS Server 5.0.8 by the time the research went public, and CISA still added all three to its KEV catalogue that day with a three-day remediation deadline.
The episode sits awkwardly for Ubiquiti: its patch was ready, but the device base is enormous and concentrated among small businesses and managed service providers, where a three-day window under CISA's new BOD 26-04 tiering is rarely achievable even with a fix already available.