AI WATCH MENA
Intelligence

Ubiquiti Patches Maximum-Severity UniFi Flaw Exposing 100,000 Devices

Ubiquiti has patched 25 vulnerabilities across its UniFi ecosystem, including a maximum-severity flaw that lets an unauthenticated attacker execute commands on the host with no credentials required. Roughly 100,000 UniFi endpoints are reachable from the public internet.

By AI Watch MENA Staff · July 9, 2026
Ubiquiti Patches Maximum-Severity UniFi Flaw Exposing 100,000 Devices

Key Takeaways

Ubiquiti has disclosed 25 security vulnerabilities across its UniFi product ecosystem, and the most severe of them clears every threshold that makes a flaw genuinely urgent: no authentication required, no user interaction, low attack complexity, and full compromise of the host device.

The flaw, tracked as CVE-2026-50746, carries a perfect CVSS score of 10.0. It sits in the UniFi Connect Application, the interface Ubiquiti customers use to manage commercial building systems such as smart lighting and electric vehicle charging infrastructure, and stems from improper access control that lets an attacker with only network reachability execute arbitrary operating system commands on the host. Ubiquiti has not published the specific technical mechanism behind the flaw, so the immediate priority is patching rather than analysis. Any organisation running UniFi Connect Application version 3.4.16 or earlier should update to 3.4.20 or later without delay.

The disclosure, published under Ubiquiti's Security Advisory Bulletin 066, does not stop at one flaw. Six additional critical vulnerabilities were patched alongside it. CVE-2026-50747, rated 9.9, is a set of authenticated SQL injection flaws in UniFi Talk that let a low-privileged attacker escalate to full host control. CVE-2026-50748, also 9.9, is a command injection flaw in UniFi Access exploitable with only low privileges. CVE-2026-54402, rated 9.9, is an SSRF vulnerability affecting UniFi OS Server that similarly allows privilege escalation with minimal starting access. CVE-2026-55115, rated 9.9, is a server-side request forgery flaw in UniFi Protect. CVE-2026-54400, rated 9.1, is an access control flaw in UniFi Access exploitable by a higher-privileged attacker. CVE-2026-55116, rated 9.0, allows unauthorised configuration changes on affected UniFi OS devices. Beyond the seven critical issues, the bulletin lists a further set of high-severity flaws, including path traversal, authentication bypass, and additional SQL injection issues, some of which Ubiquiti explicitly warns can be chained together to bypass low-privilege access requirements entirely.

What makes this disclosure particularly worth prioritising is scale of exposure rather than novelty of technique. Threat intelligence firm Censys estimates roughly 100,000 UniFi OS endpoints are currently reachable from the public internet, a substantial population of devices sitting exposed while patches roll out. UniFi hardware runs the networking, WiFi, physical security, and access control infrastructure behind a very large number of small and medium enterprises, hospitality venues, and retail locations, environments where a single internet-facing management interface can become the entry point into an entire site's network.

There is also recent precedent that argues against treating this as routine patch-cycle maintenance. A separate set of UniFi OS vulnerabilities, disclosed and patched roughly six weeks before this bulletin, was added to the US Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalogue after confirmed active exploitation. Ubiquiti has not confirmed exploitation of any of the flaws in this new bulletin as of publication, and no public proof-of-concept has surfaced for CVE-2026-50746 specifically, but the pattern from the prior chain suggests the window between disclosure and active abuse for this product family has been measured in weeks rather than months.

No interim workarounds are available for any of the flaws in this bulletin. Administrators running UniFi Connect Application 3.4.16 or earlier, UniFi Talk 5.1.2 or earlier, UniFi Access 4.2.28 or earlier, UniFi OS Server 5.1.15 or earlier, or UniFi Protect 7.1.77 or earlier should treat today's updates as immediate, not scheduled maintenance. Security teams should also restrict management-plane access to trusted networks only, rather than relying on patching alone, and review logs for unusual host or management-interface activity in the meantime. Given how frequently vulnerable network management interfaces end up as the quiet entry point behind a much larger compromise, this is exactly the kind of exposure that continuous monitoring is designed to catch before a patch window closes rather than after.

Related Articles

Intelligence

Jordan's Public Sector AI Programme: What 92% Completion Rate and Five Active AI Agent Use Cases Tell Us About MENA Government Technology

Jordan completed 78 of 85 public sector modernisation axes in H1 2026. Five AI agent use cases are now in active development across five government entities. 23 data teams assessed for maturity. This is what structured government AI adoption looks like in MENA.

Aug 17, 2026

Intelligence

AI Agents Move Into UAE Retail as Shadow AI and Governance Gaps Raise Concern

UAE retailers are moving from AI-driven insight to fully autonomous AI agents for pricing and inventory, but experts warn that fragmented systems and unmonitored "shadow AI" could expose businesses to serious governance risk.

Jul 28, 2026

Intelligence

Birchford Technologies Launches First MENA AI Translator to Fix Cross-Border Payment Compliance Gap

Birchford Technologies has launched ProLink AI Translator, the first MENA platform combining SWIFT's AI model with proprietary reference data to convert unstructured postal addresses into ISO 20022 compliant payment data ahead of a November 2026 deadline.

Jul 27, 2026

Intelligence

Anthropic Launches Claude Opus 5, Delivering Near-Frontier Performance at Half the Price

Anthropic has launched Claude Opus 5, a new frontier model delivering performance close to its top-tier Fable 5 model at half the cost, alongside what the company describes as its most aligned and safest model to date.

Jul 27, 2026

Intelligence

Abu Dhabi Launches AI-Powered Centre to Monitor 45,000 Square Kilometres of Waterways

Abu Dhabi has launched a new AI powered Waterway Monitoring and Control Centre overseeing more than 45,000 square kilometres of waterways, using predictive analytics to improve maritime safety and emergency response.

Jul 24, 2026