cbcvebase.
CVE-2026-54402
published 2026-07-02

CVE-2026-54402: A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command…

PriorityP267high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.76%
77.0th percentile
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
ubiquiti_inccloud_gateways< 5.1.195.1.19
ubiquiti_inccloud_keys< 5.1.195.1.19
ubiquiti_incdream_machines< 5.1.195.1.19
ubiquiti_incdream_routers< 5.1.195.1.19
ubiquiti_incdream_wall< 5.1.195.1.19
ubiquiti_incenterprise_firewall_core< 5.1.195.1.19
ubiquiti_incenterprise_fortress_gateway< 5.1.195.1.19
ubiquiti_incenterprise_video_recorders< 5.1.195.1.19
ubiquiti_incexpress_7< 5.1.195.1.19
ubiquiti_incnetwork_attached_storage< 5.1.195.1.19
ubiquiti_incnetwork_video_recorders< 5.1.195.1.19
ubiquiti_incunifi_os_server< 5.1.195.1.19
uienterprise_firewall_core_firmware<= 5.1.18—
uienterprise_fortress_gateway_firmware<= 5.1.15—
uienterprise_network_video_recorder_core_firmware<= 5.1.15—
uienterprise_network_video_recorder_firmware<= 5.1.15—
uiunas_2_firmware<= 5.1.16—
uiunas_4_firmware<= 5.1.16—
uiunas_pro_4_firmware<= 5.1.16—
uiunas_pro_8_firmware<= 5.1.16—
uiunas_pro_firmware<= 5.1.16—
uiunifi_cloud_gateway_fiber_firmware<= 5.1.15—
uiunifi_cloud_gateway_industrial_firmware<= 5.1.15—
uiunifi_cloud_gateway_max_firmware<= 5.1.15—
uiunifi_cloud_gateway_ultra_firmware<= 5.1.15—
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.