Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

Triple CVSS-10 Ubiquiti chain hits root

3 min read
16:08UTC

Bishop Fox chained three maximum-severity UniFi OS flaws into a public unauthenticated-root demo. CISA listed all three on 23 June with a 3-day deadline.

TechnologyDeveloping
Key takeaway

A public root exploit on millions of devices drew the new regime's fastest 3-day patch order.

Bishop Fox, a US offensive security firm, chained three flaws in Ubiquiti's UniFi OS Server, an access-control bypass (CVE-2026-34908), a path traversal (CVE-2026-34909), and a command injection (CVE-2026-34910), all scored CVSS 10.0, into a public demo that reaches unauthenticated root, then released a detection script 1. CVSS measures vulnerability severity on a scale to 10; three maximum scores in one chain is rare. Ubiquiti makes networking kit deployed widely across small businesses and prosumer estates, and it fixed all three in UniFi OS Server 5.0.8. CISA listed the trio as KEV (Known Exploited Vulnerabilities) entries on 23 June, with a 26 June deadline 2.

A working unauthenticated-root exploit is already public, against a product sitting on millions of estates, with a 3-day federal clock attached. That clock is the detail that ties this to the wider story: the Ubiquiti batch is the first KEV listing scored under BOD 26-04's top tier, the risk-tiered directive CISA issued on 10 June . Internet exposure, public exploit, and root-level impact together push it into the fastest 3-day window the new model allows, so this is the regime's debut in the wild.

UniFi sits in the same edge-device class as the small office, home office (SOHO) routers that Russian military intelligence unit GRU Unit 26165 has abused to relay credentials, but at far greater scale across business estates. Under the old directive, a CVSS 10.0 Cisco SD-WAN flaw drew an emergency 3-day order in May after the actor UAT-8616 was caught exploiting it . That speed was improvised then; BOD 26-04 now codifies it as a standing tier.

Deep Analysis

In plain English

Ubiquiti makes popular networking equipment used by small businesses, restaurants, hotels, and prosumers to manage Wi-Fi networks, switches, and security cameras from a central web interface. Approximately 4.2 million of these devices are active worldwide. Researchers at Bishop Fox found three separate security flaws in the software running on Ubiquiti's network management appliances. Each flaw on its own allows a partial intrusion. Chained together in sequence, they let an attacker gain complete control of the device without needing a username or password at all. CISA added all three to its mandatory-patch list on 23 June with a three-day deadline. Ubiquiti released a fix in version 5.0.8 of its software, and updating is urgent.

Deep Analysis
Root Causes

Ubiquiti sits in a structurally exposed position shared by all SME networking vendors: the product must be simple enough for a non-security-specialist to deploy, which means default configurations prioritise usability over isolation. UniFi's Dream Machine and Cloud Key appliances place the management web interface on the same network segment as the managed devices by default, removing the network-layer access control that would otherwise limit the exploitable surface.

The SOHO and SME networking market has no equivalent to the enterprise security review cycle that larger vendors use before shipping authentication code. GRU Unit 26165 exploited SOHO routers for Microsoft 365 credential harvesting earlier in 2026 for the same structural reason: small-footprint networking equipment has thin security teams and long patch cycles, making it a reliable initial-access surface for both state actors and criminal groups.

What could happen next?
  • Risk

    The 3-day BOD 26-04 deadline is operationally unreachable for most SME-class Ubiquiti deployments managed by MSPs; the practical patch window is 14 to 30 days, meaning a large proportion of the installed base will remain exploitable for at least two weeks after the deadline.

    Immediate · Assessed
  • Precedent

    The Ubiquiti batch is the first KEV listing to use BOD 26-04's top 3-day tier in the wild, establishing the practical compliance ceiling for the new regime; if MSPs demonstrate they cannot reach the 3-day window, it will prompt CISA to issue guidance on compensating controls for unmanageable deadlines.

    Short term · Reported
  • Consequence

    State actors and ransomware crews that exploited SOHO and SME networking equipment as initial-access vectors in 2025-2026 now have a publicly documented three-CVE chain against one of the most widely deployed SME network management platforms.

    Immediate · Assessed
First Reported In

Update #8 · CISA tears up the KEV deadline rulebook

BleepingComputer· 24 Jun 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.