Vulnerabilidades en Ubiquiti Inc

110 resultados
Análisis Vexday

Com 3 CVEs confirmadas em exploração ativa no catálogo CISA KEV, a Ubiquiti Inc apresenta uma taxa de exploração 11,9 vezes acima da média geral, o que indica histórico desproporcional de vulnerabilidades efetivamente aproveitadas por agentes maliciosos. Das 56 CVEs catalogadas, 22 são classificadas como críticas, e 15 surgiram nos últimos 90 dias, sugerindo ritmo acelerado de descoberta recente que merece acompanhamento contínuo. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), padrão que tende a viabilizar diferentes classes de ataque quando não mitigado sistematicamente. A CVE-2026-34910 se destaca como a ameaça ativa mais grave no momento, com EPSS de 0,7856 — valor que indica alta probabilidade de exploração —, e deve ser tratada com prioridade máxima por equipes que operam equipamentos Ubiquiti.

CVE-2026-54408HIGHA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to byEPSS 0.6%CVE-2026-55117HIGHA malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files EPSS 0.6%CVE-2026-22558HIGHAn Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access toEPSS 0.6%CVE-2026-77557CRITICALA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalatEPSS 0.5%CVE-2026-54400CRITICALA malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi AccesEPSS 0.5%CVE-2026-54405HIGHA malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Network Application to EPSS 0.5%CVE-2024-22054HIGHA malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device maEPSS 0.5%CVE-2025-23116CRITICALAn Authentication Bypass vulnerability on UniFi Protect Application with Auto-Adopt Bridge Devices enabled could allow a malicious actor witEPSS 0.5%CVE-2026-77549CRITICALA malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulneraEPSS 0.5%CVE-2026-47368HIGHA malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtaiEPSS 0.5%CVE-2026-55111HIGHA malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Protect Floodlight devices to accesEPSS 0.5%CVE-2026-56841HIGHA malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi PrEPSS 0.5%CVE-2026-54404HIGHA malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found EPSS 0.5%CVE-2026-50747CRITICALA malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found EPSS 0.5%CVE-2026-47369CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain deEPSS 0.5%CVE-2026-55115CRITICALA malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect ApplicatEPSS 0.5%CVE-2026-55114HIGHA malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi NetworEPSS 0.5%CVE-2026-77541CRITICALA malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi NetwoEPSS 0.5%CVE-2026-95861HIGHA malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices toEPSS 0.5%CVE-2026-77555HIGHA malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to exEPSS 0.5%