Vulnerabilities in Ubiquiti Inc

110 results
Vexday analysis

Com 3 CVEs confirmadas em exploração ativa no catálogo CISA KEV, a Ubiquiti Inc apresenta uma taxa de exploração 11,9 vezes acima da média geral, o que indica histórico desproporcional de vulnerabilidades efetivamente aproveitadas por agentes maliciosos. Das 56 CVEs catalogadas, 22 são classificadas como críticas, e 15 surgiram nos últimos 90 dias, sugerindo ritmo acelerado de descoberta recente que merece acompanhamento contínuo. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), padrão que tende a viabilizar diferentes classes de ataque quando não mitigado sistematicamente. A CVE-2026-34910 se destaca como a ameaça ativa mais grave no momento, com EPSS de 0,7856 — valor que indica alta probabilidade de exploração —, e deve ser tratada com prioridade máxima por equipes que operam equipamentos Ubiquiti.

CVE-2026-34910CRITICALA malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute aEPSS 45.8%KEVCVE-2025-52665CRITICALA malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, tEPSS 41.0%CVE-2026-22557CRITICALA malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access fEPSS 28.1%CVE-2026-34908CRITICALA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthEPSS 15.2%KEVCVE-2026-34909CRITICALA malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the uEPSS 1.8%KEVCVE-2026-54402CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS tEPSS 1.8%CVE-2026-50746CRITICALA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to exEPSS 1.7%CVE-2026-77552CRITICALA malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Video EPSS 1.6%CVE-2026-77537CRITICALA malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to EPSS 1.6%CVE-2026-77554CRITICALA malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to exeEPSS 1.6%CVE-2026-50748CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi AcceEPSS 1.6%CVE-2026-77546CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi AcceEPSS 1.4%CVE-2026-77548CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi ProtEPSS 1.4%CVE-2026-77533CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi ProtEPSS 1.4%CVE-2026-47370CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain deEPSS 1.4%CVE-2026-77543CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi AcceEPSS 1.4%CVE-2026-47367CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID EnterpEPSS 1.4%CVE-2026-77547CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi AcceEPSS 1.4%CVE-2026-33000CRITICALA malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS EPSS 1.4%CVE-2023-38034HIGHA command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, couldEPSS 1.4%