CVE-2026-54402
published 2026-07-02CVE-2026-54402: A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command…
PriorityP267high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.76%
77.0th percentile
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ubiquiti_inc | cloud_gateways | < 5.1.19 | 5.1.19 |
| ubiquiti_inc | cloud_keys | < 5.1.19 | 5.1.19 |
| ubiquiti_inc | dream_machines | < 5.1.19 | 5.1.19 |
| ubiquiti_inc | dream_routers | < 5.1.19 | 5.1.19 |
| ubiquiti_inc | dream_wall | < 5.1.19 | 5.1.19 |
| ubiquiti_inc | enterprise_firewall_core | < 5.1.19 | 5.1.19 |
| ubiquiti_inc | enterprise_fortress_gateway | < 5.1.19 | 5.1.19 |
| ubiquiti_inc | enterprise_video_recorders | < 5.1.19 | 5.1.19 |
| ubiquiti_inc | express_7 | < 5.1.19 | 5.1.19 |
| ubiquiti_inc | network_attached_storage | < 5.1.19 | 5.1.19 |
| ubiquiti_inc | network_video_recorders | < 5.1.19 | 5.1.19 |
| ubiquiti_inc | unifi_os_server | < 5.1.19 | 5.1.19 |
| ui | enterprise_firewall_core_firmware | <= 5.1.18 | — |
| ui | enterprise_fortress_gateway_firmware | <= 5.1.15 | — |
| ui | enterprise_network_video_recorder_core_firmware | <= 5.1.15 | — |
| ui | enterprise_network_video_recorder_firmware | <= 5.1.15 | — |
| ui | unas_2_firmware | <= 5.1.16 | — |
| ui | unas_4_firmware | <= 5.1.16 | — |
| ui | unas_pro_4_firmware | <= 5.1.16 | — |
| ui | unas_pro_8_firmware | <= 5.1.16 | — |
| ui | unas_pro_firmware | <= 5.1.16 | — |
| ui | unifi_cloud_gateway_fiber_firmware | <= 5.1.15 | — |
| ui | unifi_cloud_gateway_industrial_firmware | <= 5.1.15 | — |
| ui | unifi_cloud_gateway_max_firmware | <= 5.1.15 | — |
| ui | unifi_cloud_gateway_ultra_firmware | <= 5.1.15 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.
ghsa_unreviewed·2026-07-02
CVE-2026-54402 [CRITICAL] CWE-20 A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.
VulDB
Ubiquiti UniFi OS Server prior 5.1.19 input validation
vuldb·2026-07-02·CVSS 9.9
CVE-2026-54402 [CRITICAL] Ubiquiti UniFi OS Server prior 5.1.19 input validation
A vulnerability described as critical has been identified in Ubiquiti UniFi OS Server, Dream Machines, Enterprise Fortress Gateway, Dream Wall, Dream Routers, Express 7, Cloud Keys, Network Video Recorders, Enterprise Video Recorders, Cloud Gateways, Network Attached Storage and Enterprise Firewall Core. This issue affects some unknown processing. Executing a manipulation can lead to improper input validation.
This vulnerability is registered as CVE-2026-54402. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
blogs_hackernews·2026-07-13
CVE-2026-50746 ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That's supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don't file tickets.
That's the shape of this week. Trusted code turns on the people who installed it. Old bugs from last year are still landing because the fix sat in a queue too long. Fake installers, poisoned packages, systems left facing the open internet, and helpful little AI assistants running instructions that were
Hackernews
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
blogs_hackernews·2026-07-08·CVSS 10.0
CVE-2026-50746 [CRITICAL] Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and arbitrary command execution.
The list of vulnerabilities is as follows -
CVE-2026-50746 (CVSS score: 10.0) - An improper access control vulnerability in UniFi Connect Application that an attacker with access to the network could exploit to execute a command injection on the host device. (Affects versions 3.4.16 and earlier; fixed in version 3.4.20
2026-07-02
Published