Ubiquiti Patches Three Critical Bugs in UniFi Cameras, Phones and Router OS
Flaws in UniFi Protect, UniFi Talk and UniFi OS score the highest possible severity and can be triggered over the network without a login.

Key points
- Ubiquiti released fixes for three maximum-severity flaws in its UniFi camera, phone and router software.
- All three carry a perfect 10 out of 10 severity score and can be exploited remotely, with no password or user interaction required.
- Fixed versions are UniFi Protect Application 7.2.105, UniFi Talk Application 5.3.2, and UniFi OS Server 5.1.21 or later.
- Censys tracks more than 100,000 UniFi OS instances exposed on the public internet.
- Ubiquiti patched 18 additional critical bugs across its wider product line the same week.
Ubiquiti has shipped fixes for three perfect-score flaws in the software powering its UniFi security cameras, VoIP phones and network routers. No login required. No click from a victim.
The company sells networking equipment to small businesses, home labs and schools. It disclosed the flaws through its advisory portal alongside patched builds.
What are the three flaws?
All three score the maximum 10 out of 10 and let a remote attacker reach the device without credentials.
CVE-2026-77537 sits in UniFi Protect, the platform that manages Ubiquiti's video cameras. Improper input validation, meaning the software accepts data it should reject, lets an attacker compromise a camera server without ever logging in.
CVE-2026-77550 is a CRLF injection bug in UniFi OS, the operating system on Ubiquiti's routers and gateways. CRLF injection means hidden line-break characters slipped into a web request can confuse the device into skipping authentication entirely.
CVE-2026-77554 is a command injection flaw in UniFi Talk, Ubiquiti's VoIP phone system. An attacker smuggles instructions directly into the device, effectively taking the wheel.
Which versions are safe?
Admins need UniFi Protect Application 7.2.105 or above, UniFi Talk Application 5.3.2 or above, and UniFi OS Server build 5.1.21 or above.
| Product | Flaw | Fixed in |
|---|---|---|
| UniFi Protect Application | CVE-2026-77537 | 7.2.105 |
| UniFi OS Server | CVE-2026-77550 | 5.1.21 |
| UniFi Talk Application | CVE-2026-77554 | 5.3.2 |
Ubiquiti hasn't confirmed whether any of the three were exploited before the patches went out. It did say they're reachable via low-complexity attacks with no user interaction, which is exactly what mass scanners hunt for.
Also that week, first reported by BleepingComputer, Ubiquiti patched 18 more critical bugs affecting the UniFi Network Application, the UniFi Protect AI Key appliance, and a broad range of routers, gateways, NAS boxes and cameras.
Should users be worried?
Yes. Any UniFi device reachable from the internet should be patched immediately.
Censys tracks more than 100,000 exposed UniFi OS instances online, though that figure may include historical scan results and researcher-deployed honeypots, so the real count of vulnerable live systems is unclear. Even a fraction of it is a substantial target list.
Ubiquiti hardware has a documented history of being drafted into criminal and state operations. In February 2024, the FBI dismantled Moobot, a botnet of Ubiquiti Edge OS routers the Russian GRU used to proxy espionage traffic. CISA later mandated that federal agencies patch three other max-severity UniFi OS vulnerabilities within three days after they were found being actively exploited; Bishop Fox subsequently showed those flaws could be chained for full remote code execution with elevated privileges. Our 19 August report on the Dahua camera hijack campaign is a useful reminder of how quickly exposed devices get absorbed into attack infrastructure once a credible bug is public.
Home and small-business owners running UniFi gear should open the UniFi console now, compare their installed versions against the fixed builds above, and apply updates. If remote console access isn't needed, disable it at the router.



