Ubiquiti Patches Three Critical Bugs in UniFi Cameras, Phones and Router OS

Flaws in UniFi Protect, UniFi Talk and UniFi OS score the highest possible severity and can be triggered over the network without a login.

ThreatVectr Newsdesk· 3 min read
A modern white robot vacuum cleaner sitting on a wooden living room floor, its top cover removed to expose a green circuit board and a small memory chip, warm d
Share

Key points

  • Ubiquiti released fixes on November 20, 2025 for three maximum-severity flaws in its UniFi camera, phone and router software.
  • All three carry the top severity rating and can be triggered remotely, with no password and no user interaction.
  • Fixed versions are UniFi Protect Application 7.2.105, UniFi Talk Application 5.3.2, and UniFi OS Server later than 5.1.21.
  • Censys currently sees more than 100,000 UniFi OS devices exposed on the public internet.
  • Ubiquiti also patched 18 further critical bugs across its wider product line the same week.

Ubiquiti has shipped emergency fixes for three top-severity holes in the software that runs its popular UniFi security cameras, office phones and network routers. Each one can be attacked straight over the network, with no login and no click from a victim.

The company, which sells networking gear used by small businesses, schools and home labs, disclosed the flaws in its security advisory portal alongside patched builds.

What are the three flaws?

All three are rated the maximum severity of 10 out of 10 and let an attacker on the network reach the device without any credentials.

The first, CVE-2026-77537, sits in UniFi Protect, the software that manages Ubiquiti's video cameras. Because the program does not properly check the data sent to it, an attacker can take over an unpatched camera server remotely.

The second, CVE-2026-77550, is a CRLF injection bug in UniFi OS, the operating system on Ubiquiti routers and gateways. CRLF injection means an attacker slips hidden line breaks into a web request to confuse the device, and in this case that trick is enough to skip the login screen entirely.

The third, CVE-2026-77554, is a command injection bug in UniFi Talk, Ubiquiti's office phone system. Command injection lets an attacker smuggle in their own instructions for the device to run, effectively handing them control of the phone platform.

Which versions are safe?

Admins need to be on UniFi Protect Application 7.2.105 or later, UniFi Talk Application 5.3.2 or later, and any UniFi OS Server build newer than 5.1.21.

Product Flaw Fixed in
UniFi Protect Application CVE-2026-77537 7.2.105
UniFi OS Server CVE-2026-77550 later than 5.1.21
UniFi Talk Application CVE-2026-77554 5.3.2

Ubiquiti has not said whether any of the three bugs were used in real attacks before the patches went out. It did confirm they can be exploited in "low-complexity" attacks with no user interaction, which is the profile mass scanners look for.

The same week, first reported by BleepingComputer, the company also fixed 18 more critical bugs affecting UniFi OS Server, the UniFi Network Application, the UniFi Protect AI Key appliance, and a long list of Ubiquiti routers, gateways, storage boxes and cameras.

Should users be worried?

Yes, if a UniFi device is reachable from the internet, it should be patched today.

Internet scanning firm Censys currently sees more than 100,000 UniFi OS devices exposed online, although that figure includes older scan data and some honeypot decoys set up by researchers. Even a fraction of that is a large target list.

Ubiquiti kit has a track record of being pulled into criminal and state operations. In February 2024, the FBI dismantled Moobot, a botnet of Ubiquiti Edge OS routers used by Russia's GRU military intelligence agency to hide its hacking traffic. In June, the US Cybersecurity and Infrastructure Security Agency gave federal agencies three days to fix a different set of maximum-severity UniFi OS bugs that were already being attacked in the wild. Security firm Bishop Fox showed those earlier flaws could be chained together for full remote takeover.

Home and small business owners who run UniFi gear should open the UniFi console, check the software version against the fixed builds above, and apply updates. If remote access to the console is not needed, turn it off at the router.

© 2026 Threat Vectr