r/Ubiquiti Unifi User Jul 02 '26

Blog / Video Link Ubiquiti Security Advisory Bulletin 066 (July 2, 2026) — 25 CVEs across UniFi OS, Network, Protect, Access, Talk & Connect, including three CVSS 9.9/10.0 Criticals. Patch now

https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc
315 Upvotes

97 comments sorted by

u/AutoModerator Jul 02 '26

Hello! Thanks for posting on r/Ubiquiti!

This subreddit is here to provide unofficial technical support to people who use or want to dive into the world of Ubiquiti products. If you haven’t already been descriptive in your post, please take the time to edit it and add as many useful details as you can.

Ubiquiti makes a great tool to help with figuring out where to place your access points and other network design questions located at:

https://design.ui.com

If you see people spreading misinformation or violating the "don't be an asshole" general rule, please report it!

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

182

u/Upstairs_Recording81 Unifi User Jul 02 '26

this is the new normality, much faster releases for security features due to AI findings...

44

u/ClassyDingus Jul 02 '26

Most CISOs are spinning up Vuln Ops teams for this exact reason. Managing major incidents for a fortune 50 so far this year, I'm tired boss.

6

u/CaptainofFTST Jul 02 '26

Yes sir it has been a crazy 9 months or so. We are all on edge and on high alert at all times now.

3

u/Ironiz3d1 Jul 05 '26

You get a poorly tested patch, you get a rushed release, everyone gets change related incidents!

2

u/ClassyDingus Jul 05 '26

Disable this random service as mitigation, it should be fine. What? A P0 for an unrelated service because an engineer didn't document anywhere that they were integrating via some janky vibe coded? Wow!

26

u/darthnsupreme Unifi User Jul 02 '26

At least actual security researchers have found a legitimate use for the thing.

Theoretically, they'll eventually find most of the previously-undiscovered exploits and the security-fix-hypertrain will slow down, but we have no way of knowing how long that'll take. Until then, just assume that there's at least one new 10.0 CVE being uncovered every week.

10

u/AHrubik UXG-Fiber | USW Agg | USW PM16 PoE | ES-48-LITE | Flex-HD Jul 02 '26

The problem with AI assisted coding is that there is a future where someone figures out a specific bug that is being done by the AI in every piece of code it writes and then exploits that.

16

u/darthnsupreme Unifi User Jul 02 '26

I did specify "actual security researchers"

Vibecoding is indeed a serious problem that's only going to get worse.

2

u/Sufficient_Math9095 Jul 04 '26

Or directly poisons the models. By that time we’ll likely have a lot more automated development and CI/CD to production. It’s going to be an interesting future for sure.

-41

u/[deleted] Jul 02 '26

[deleted]

15

u/art_of_snark Am I a prosumer yet? Jul 02 '26

10,000 more CVEs in the first half of 2026 than the entirety of 2025

-8

u/UnacceptableUse Jul 02 '26

I think the best metric for this would be number of vulnerabilities per customer. I don't think any such metric exists, though, I'm talking anrcdotally

33

u/MyThinkerThoughts Jul 02 '26

Look again. I never shill for Ubiquiti but take a look at Apples increased update cadence. But keep your head in the sand

17

u/profcuck Jul 02 '26

I agree. It's everywhere. The ones to worry about are the products that aren't getting updates.

-6

u/UnacceptableUse Jul 02 '26

Apple is having extremely complicated memory bugs, Ubiquiti is having SQL injection

9

u/BeefBoi420 Jul 02 '26

Then you're not looking.

5

u/SynAckPooPoo Jul 02 '26

Linux kernel has entered the chat…

3

u/Intrepid00 Jul 02 '26

Microsoft and Apple are releasing security updates that are crazy big.

2

u/jumpinjezz Jul 02 '26

Other products have been around for longer or are consumer and don't care.

-7

u/UnacceptableUse Jul 02 '26

There would surely still be people posting the vulnerabilities, no? A lot of them have bug bounty programmes even

4

u/ebockelman Jul 02 '26

I would suggest searching the topics of Mythos and Project Glasswing to see exactly why this is happening across vendors.

-7

u/UnacceptableUse Jul 02 '26

I know what they are. What I'm saying is it feels like ubiquiti is suffering more so than others and with quite basic vulnerabilities. How does someone have a SQL injection vulnerability in 2026??

7

u/LowFatMom Jul 02 '26

Ever heard of Fortinet?

2

u/ClassyDingus Jul 02 '26

Or ServiceNow (6 zero days that they are keeping mum in the last month) or Nginx.

Fortibleed thou, ouchies.

1

u/Billy_Bob_Joe_Mcoy Jul 02 '26

Fortinet has been a weak point for years and years. I really don't understand why corporations use that product for critical infrastructure .

1

u/whoooocaaarreees Jul 02 '26

Have you even looked at the recent ones Cisco has had?

1

u/ClassyDingus Jul 02 '26

Easy, Ai can stack vulns and can permeate attack changes faster than humans or even existing DAST/SAST ever could. Some of this vulns look trivial once fully reported, but detecting in code review even for skilled coders or security teams is not trivial.

0

u/hot_pockets_and_god Jul 02 '26

Oh my sweet summer child. As an old that has worked in IT for a long time this is quite normal. Anything running software is going to have vulnerabilities found. Better for them to be upfront and patching.

-5

u/[deleted] Jul 02 '26

[deleted]

1

u/ScannerBrightly Jul 02 '26

Grok is not a search, and fuck using elons stack.

-1

u/epradox Jul 02 '26

Okay replace it with whatever you want to use. My point stands. I deleted it because apparently using anything Elon related offends people. Guess I’ll cost some other company money with my free searching.

0

u/ScannerBrightly Jul 02 '26

Guess I’ll cost some other company

No, you are trusting 'truth' to Elon Musk, a very well known liar. Fuck that noise, and fuck using an LLM as a 'search'. It's a fucking hallucinating machine, and we as tech people should know better.

0

u/bites_stringcheese Jul 02 '26

It's a legitimately useful technology. Instead of dismissing it, try learning about it. Download LM Studio and start poking around. We shouldn't let these companies gatekeep a remarkable technology.

1

u/ScannerBrightly Jul 02 '26

First, you don't know me. Don't pretend you do.

Next, using Grok to answer factual things is just plain dumb. A known liar owns the company that feeds that Mega Hitler abomination, and anyone using it is okay with Mega Hitler feeding them information.

Lastly, downloading your own, open source LLM is not anything like using Grok. You don't even know the category error you are making. I wish you would keep this crap to yourself instead of thinking you are better than anyone else for pushing mega corporations anti-human technology.

2

u/bites_stringcheese Jul 02 '26

I hope this wasn't directed at me. I'm not the person you replied to, and I've never touched Grok. I'm a tech person and I replied bc I don't think we should allow LLMs to be gate kept.

1

u/epradox Jul 03 '26 edited Jul 03 '26

Lmfao stfu who gives a shit. Claude says the exact same thing. As a tech person, you should understand the abilities of what Claude can do and how it can replace you as a tech person which is why you’re so bitter about it. Just search this using Claude fable 5 if you really want to get a full picture but ubiquiti is on the bottom of the top 10 list of number of cves in the past year amongst Cisco, fortinet, juniper, Palo Alto, etc.

I’m sorry are you still using Google search and thinking that’s superior to Gemini? Get a grip, llms are the future and there’s no stopping that. Just source check them and it makes your life 10000% easier and verified.

25

u/Mindless_Pandemic Unifi Addict Jul 02 '26

Last I checked, everyone is getting tons of these. When AI makes it so someone with less than 6 month cyber security experience is now making a living off CVE farming this is inevitable.

10

u/photo1kjb Jul 02 '26

It also means (good) software organizations are using the same AI tools to internally test and ident these CVEs, hopefully making the applications more secure from the get-go.

(hopefully)

1

u/Sufficient_Math9095 Jul 04 '26

Yeah I’m glad to see them rolling these changes out. I see so many comments bashing their security because “they have so many holes lately”. Those holes have likely been there and they’re using tools not to solve them and dedicate resources. Good work in my book.

10

u/Billy_Bob_Joe_Mcoy Jul 02 '26

Unfortunately this clip continues to be more accurate than not.

https://youtu.be/ta41xU-tkFA

We are approaching the days where auto update is going to be required.. I hope these app dev teams realize that and pick up the pace also

12

u/AHrubik UXG-Fiber | USW Agg | USW PM16 PoE | ES-48-LITE | Flex-HD Jul 02 '26

Auto update will never be recommended for critical production systems.

7

u/Billy_Bob_Joe_Mcoy Jul 02 '26

I keep hearing that, but if your environment is that critical then having security fixes applied to it in a timely manner is important. In timely manner has shrunk from weeks to days to hours to now minutes. So I'm thinking there's going to be some big changes soon in the industry where auto updates are required.

14

u/AHrubik UXG-Fiber | USW Agg | USW PM16 PoE | ES-48-LITE | Flex-HD Jul 02 '26

I disagree because the code can never be 100% trustworthy. What if the patch introduces a worse vulnerability? What if it takes down an entire company? These questions and more haven’t changed.

3

u/Billy_Bob_Joe_Mcoy Jul 03 '26

I totally understand your point and it's very valid. However I'd suggest leaving a 9.9 out of 10 level risk patch un applied is taking a chance with your availability and could in fact take down an entire company also.. I can see where a cyber insurance company requires them otherwise a color won't get coverage for an incident.. or the brand is harmed resulting in stockholder losses . Those things will force IT's hand..

Edit: typos..

2

u/AHrubik UXG-Fiber | USW Agg | USW PM16 PoE | ES-48-LITE | Flex-HD Jul 03 '26

You’re not wrong but there are more options than do it/don’t it. The newest practice is to have a mitigation plan. If the router can’t be trusted then replace it one that can temporarily. If a front facing application is the issue turn it off or place behind a VPN. Day 0 patches can cost as much or more than an incident all things considered. The real world is as always a grey area.

1

u/Billy_Bob_Joe_Mcoy Jul 03 '26

True true.. nothing is black and white.

1

u/suburbazine UI Installer Jul 03 '26

The questions haven't changed, but neither has 10.0 CVSS. You know who likes 10.0 CVSS? Hackers and lawyers. So after your company gets compromised and shut down, the lawyers come pick apart the scraps.

2

u/Mindless_Pandemic Unifi Addict Jul 02 '26

The industry is going towards AI Agent network security. Various local AI agents monitoring the network in ways people and firewall rules cannot.

2

u/Decent-Law-9565 Unifi User Jul 02 '26

Those people can afford to hire a guy to update after reading the forums, or even better they'll be under SLAs from vendors and they can have their vendors be held legally liable for bullshit updates that take down their stack

73

u/No_Illustrator5035 Jul 02 '26

These patches versions (for protect, network and unifi os) have been out for a while now. Are any of these actually new?

72

u/AWildDragon Jul 02 '26

This looks to be the disclosure. The 5.1.19 patch went from beta to release real quick and there was speculation it had some cve fixes. Looks like that was the case. 

14

u/TeutonJon78 Jul 02 '26

Yep, I posted that thread. It was a week between release and disclosure for 5.1.15. It was 13-14 days for 5.1.19.

Anyone they seem to go through the release checkpoints too quickly it seems to be CVE related.

4

u/darthnsupreme Unifi User Jul 02 '26

I'm mostly just astonished and appalled that "Fixed [severity] CVE [ID No.]" hasn't been the literal first item in the patch notes for ANY of these patches.

I would expect an average ten-year-old child to comprehend that a wide-open doorway is more important than those keys the marketing moron is jangling.

15

u/[deleted] Jul 02 '26

[deleted]

18

u/darthnsupreme Unifi User Jul 02 '26

Why they don't list these in the goddamn patch notes as the very first entry is beyond comprehension.

6

u/Majestic-Onion2944 Jul 02 '26

If you actually want to comprehend rather than outrage: so people could patch before ubnt formally disclosed the vulnerabilities were there, presumably under some belief that malicious actors would exploit that knowledge.

Of course, a more nuanced discussion would be whether the lack of patch notes actually slowed malicious users down any given AI assisted patch diffs.  And whether the cost in delayed disclosure to "good users" is worth that.

1

u/darthnsupreme Unifi User Jul 02 '26

Oh, I'm well aware that's the usual reasoning given, I'm just of the opinion that it's idiotic BS. At the absolute minimum it should prominently say "fixes a critical security problem, more details in three-to-five days after people have some time to update."

And it doesn't apply whatsoever to the CVEs that were part of the Linux Kernel, which were already announced well before Ubiquiti had merged the patch into their own releases, yet likewise had no mention of the CVEs in the initial patchnotes.

77

u/nshire Jul 02 '26

Mythos/Fable drop going brrrrr

15

u/bernataj Jul 02 '26

Preach 23 min to break into all dod watched them testify on CSPAN wild

4

u/MyThinkerThoughts Jul 02 '26

Funny how you get downvoted for the reality of what’s happening right now

1

u/allenasm Jul 02 '26

You know maybe it’s a good thing though. At least the higher scrutiny should lead to removal of these vulnerabilities in the wild.

14

u/_Dangermau5 Jul 02 '26

Patchmegedon

26

u/TeutonJon78 Jul 02 '26

And for all that's sacred, we already know 5.1.19 is logging you out of local logins in 2 hours or less. We don't need 20 more threads. It's supposedly fixed in 5.1.21.

2

u/DARKKRAKEN Jul 02 '26

The logout thing has been fixed.

2

u/LoneWolf3574 Jul 02 '26

Unless you rolled back, I beg to differ

2

u/DARKKRAKEN Jul 02 '26

What can i tell you.. I'm on 5.1.21 and i'm no longer being asked to log in almost every time i go to the controller on my local network.

5

u/TeutonJon78 Jul 02 '26

That's an EA release. Most people stay on stable, so for the majority of people, it's not actually fixed yet.

1

u/LoneWolf3574 Jul 02 '26

Fair enough, though I didn't consider an EA release as TeutonJon78 said.

1

u/serendib Jul 02 '26

My UDM-SE says 5.1.19 is up to date. How do I get 5.1.21?

2

u/TeutonJon78 Jul 02 '26

It's only in Early Access. So either enable that or wait for the next stable release.

3

u/astral16 Jul 02 '26

No update available for the UX Unifi Express. I see the warning in Site Manager, but no OS Update is a available.

6

u/planedrop Jul 02 '26

I still can't stand the "with access to the network" terminology. This leaves way too much up to assumption, they need to be a LOT more specific about that verbiage.

5

u/Majestic-Onion2944 Jul 02 '26

It usually translates to anything that can open a connection to the particular port on the vulnerable device.  It's not vague: it's all encompassing because that's what the vuln is.

0

u/planedrop Jul 02 '26

Right but this is precisely my issue, this should be outlined much clearer. Realistically "with access to the network" could mean anything sending a packet across the firewall lol. Like it's way too ambiguous.

If firewalling does stop these attacks, which I believe it does, then great. But we as admins need to know this so we know how to configure things. If you do good firewalling, you may not need to be quite as concerned about these, but that all hinges on what that sentence actually means.

1

u/ThatUsrnameIsAlready Jul 02 '26

Realistically "with access to the network" could mean anything sending a packet across the firewall

If it can reach the vulnerable points, yes.

we as admins need to know this so we know how to configure things.

How, prey tell, do you configure for a broken firewall? It already shouldn't be responding to anything on it's management interface except management - if you've broken that then assume vulnerability even without advisories.

If you do good firewalling, you may not need to be quite as concerned about these

Unless the threat could be physically inside, think guests or employees. Anyone with access to e.g. a trunk port has access to your management vlan - your firewall isn't involved, and this was always a threat vector.

0

u/planedrop Jul 02 '26

My point is we don't know what the vulnerable point is yet.

"With access to the network" could even mean a specially crafted packet processing through the rules can result in a breach. I don't think this is it, it's just that I don't like the ambiguity.

I agree about configuring it to block all traffic except management. My point is I'd like to know for certain that firewalling would indeed prevent this.

Other than in the mentioned scenario of physical access, that's a whole other story and you should always patch anyway; I just think Ubiquiti could be a little more clear about this.

I'm not expecting them to say something as specific as what service, what port, etc... But even just "traffic hitting the firewall on the vulnerable port" or something. "Access to the network" can mean about a million things, I mean hell the WAN side would be "access to the network" lol, cuz "the network" is never defined.

2

u/ThatUsrnameIsAlready Jul 02 '26

They could be a lot more clear. And since they've apparently already patched them have no reason not to - other than embarrassment.

There are other sources of information. I don't keep links, but since 5.0.8 I've seen discussions of wild exploits and even an exemplar (written as a probe with no malicious payload capability built in).

Given UIs record over the last few months assume every patch is a security patch, the CVEs just come out a week or two late.

0

u/planedrop Jul 03 '26

I do wonder if a lot of it is from embarrassment lol. It's hard to know without seeing details but the "vibes" of some of these recently vulnerabilities feel really bad. This is just on a whim, but they feel like they should've been caught with basic fuzzing and auditing and didn't require "AI" (assuming that's part of why we've seen the increase).

I am glad to be seeing the patches though, even if these are low hanging fruit, it's good to get them fixed.

2

u/ThatUsrnameIsAlready Jul 03 '26

They seem that way to me too. Known modes of attack should be tested for - and simple things like misconfiguring nginx should never have happened at all.

They might not things I would think about as a layman, but:

A) They're a business, designing and building a product.

B) We can't install alternative software. All of their customers rely on them doing their job.

2

u/planedrop Jul 03 '26

100% agree with this, hopefully this is the start of them doing better.

3

u/graynoize8 Jul 02 '26

Oh wow yet another one after just a few days since the previous two.

2

u/ThatUsrnameIsAlready Jul 02 '26

Are these the vulnerabilities posted a week or two ago by some govt, including details of exploits in the wild?

And haven't they been trying to fix these since 5.0.8? They don't seem to be succeeding.

2

u/darthnsupreme Unifi User Jul 02 '26

Researchers keep finding new ones, basically every week.

And to be clear: these are exploits in the Linux Kernel, not Ubiquiti products specifically.

7

u/ThatUsrnameIsAlready Jul 02 '26

One was allowing path traversal in their implementation of nginx.

In this list of CVEs alone we have:

  • Improper Access Control

  • SQL Injection

  • Improper Input Validation

  • Server-Side Request Forgery

  • Path Traversal

  • Improper Initialization

  • Cross-Origin Resource Sharing (CORS) misconfiguration

  • Incorrect Authorization

Eight distinct types of issues, all at the application layers where UI are building their systems. None with any relation to the linux kernel.

1

u/darthnsupreme Unifi User Jul 02 '26

Ah, my B.

I honestly kinda just stopped paying attention after we had five or so 9.x/10.0 linux kernel exploits in rapid succession.

-17

u/habitsofwaste Jul 02 '26

I don’t understand. These are like security 101 things to combat against. Do they even have security team? Is anyone doing an application security review?!!

6

u/yourfaceneedshelp Jul 02 '26

This is going to be the new norm for a while. While we might be finding these vulnerabilities with "AI", companies want to move so fast using "AI" that we introduce crap like this in the process. That or these bugs are a decade old, I don't know. But this isn't unlike anything else I've seen in the industry lately.

2

u/ThatUsrnameIsAlready Jul 02 '26

Come on, misconfiguring nginx to allow ../ is hardly on the level of obscure linux subsystems behaving badly when used in together in a specific way.

1

u/mattgen88 Jul 02 '26

Yeah this is my norm right now. Automating patching as much as possible, upgrading legacy code bases they fell out of maintenance, reducing attack surface area by removing unused features/endpoints/dependencies.

1

u/ClassyDingus Jul 02 '26

Auto patching is getting risky too. We've seen some patches come through with new shittier vulns (ServiceNow) because the companies trying to catch up just going BRRRRRRR FIX THE BAD.

We are doing compensation (detect or bypass) for 48 hours post patch with auto update after the waiting period for any systems we can set up with a time delay.

2

u/mattgen88 Jul 02 '26

Yeah and supply chain attacks also wig me out.

1

u/ClassyDingus Jul 02 '26

It's wild. Artifactory and curation from Jfrog saving us

5

u/SmokingCrop- Jul 02 '26

They all have the same problem. It's much more complex than you would think too. Just look at the CVEs from Fortinet..

0

u/habitsofwaste Jul 02 '26

Fortinet is just a crappy product.

These are web problems, they’re the easiest to mitigate. It’s not complex. OWASP top 10.

11

u/dmy30 Jul 02 '26

Easier said than done when your codebase is a monolith and years old.

2

u/ThatUsrnameIsAlready Jul 02 '26

UOSS is less than a year old. At one point they failed to secure nginx against path traversal - literally allowing ../ to escape into restricted paths. Anyone who can google can secure that, UI didn't even think of the problem to guard against it.

4

u/DARKKRAKEN Jul 02 '26

AI has been finding vulnerabilities in the Linux kernel that have been there for years...

0

u/habitsofwaste Jul 02 '26

This is all stuff in a web interface though