UniFi OS Server unauthenticated root RCE chain (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
UniFi OS Server is exposed to an unauthenticated root RCE chain that combines CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, putting versions 5.0.6 and earlier at risk. Researchers validated the chain on a live 5.0.6 instance and showed that it can reach root without credentials or user interaction. The flaws were fixed in May, and defenders can confirm exposure with a free detection script before upgrading to 5.0.8 or later.
Related Happenings
F5 BIG-IP APM active exploitation wave (CVE-2025-53521)
Exploitation Wave
H score79
First: 02.04.2026 11:25
Last: 02.04.2026 11:25
Sources 1
About this happening:
As of 2026-04-02, ongoing attacks are exploiting CVE-2025-53521 against F5 BIG-IP APM systems, leaving more than 14,000 exposed online and at risk of remote code e...
F5 BIG-IP APM active exploitation wave (CVE-2025-53521)
Exploitation WaveAbout this happening: As of 2026-04-02, ongoing attacks are exploiting CVE-2025-53521 against F5 BIG-IP APM systems, leaving more than 14,000 exposed online and at risk of remote code e...
CISA KEV patch order for Dell RecoverPoint
Public Sector Action
H score36
First: 19.02.2026 17:30
Last: 19.02.2026 17:30
Sources 1
About this happening:
CISA added CVE-2026-22769 to the KEV catalog and ordered Federal Civilian Executive Branch agencies to secure their networks by February 21. The directive unde...
CISA KEV patch order for Dell RecoverPoint
Public Sector ActionAbout this happening: CISA added CVE-2026-22769 to the KEV catalog and ordered Federal Civilian Executive Branch agencies to secure their networks by February 21. The directive unde...
UNC6201 Dell RecoverPoint for Virtual Machines zero-day campaign
Campaign
H score44
First: 17.02.2026 22:15
Last: 17.02.2026 22:15
Sources 1
About this happening:
The UNC6201 campaign has been exploiting a Dell zero-day since mid-2024, creating a sustained risk of unauthorized access and stealthy movement across victims' virtual...
UNC6201 Dell RecoverPoint for Virtual Machines zero-day campaign
CampaignAbout this happening: The UNC6201 campaign has been exploiting a Dell zero-day since mid-2024, creating a sustained risk of unauthorized access and stealthy movement across victims' virtual...
Latest development: 19.02.2026 17:30
CISA added CVE-2026-22769 to its Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to secure affected Dell RecoverPoint systems by Saturday, February 21, after Mandiant and Google Threat Intelligence Group (GTIG) said UNC6201 had exploited the flaw since at least mid-2024.
BeyondTrust Remote Support and Privileged Remote Access CVE-2026-1731 active exploitation wave
Exploitation Wave
H score76
First: 12.02.2026 23:34
Last: 12.02.2026 23:34
Sources 1
About this happening:
CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access is now seeing first in-the-wild exploitation, putting exposed appliances at risk of remote...
BeyondTrust Remote Support and Privileged Remote Access CVE-2026-1731 active exploitation wave
Exploitation WaveAbout this happening: CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access is now seeing first in-the-wild exploitation, putting exposed appliances at risk of remote...
CISA adds three exploited vulnerabilities to KEV with federal remediation deadline
Public Sector Action
H score35
First: 15.10.2025 12:23
Last: 15.10.2025 12:23
Sources 1
About this happening:
CISA added three exploited vulnerabilities to the KEV catalog, requiring federal agencies to apply the patches by November 4, 2025. The action turns already ex...
CISA adds three exploited vulnerabilities to KEV with federal remediation deadline
Public Sector ActionAbout this happening: CISA added three exploited vulnerabilities to the KEV catalog, requiring federal agencies to apply the patches by November 4, 2025. The action turns already ex...
Timeline
-
24.06.2026 15:32 1 articles · 21d ago
CISA adds UniFi OS Server CVEs to KEV after in-the-wild exploitation reports
Exploitation ObservedCISA added CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 to the Known Exploited Vulnerabilities (KEV) catalog after warnings that threat actors were targeting UniFi OS Server devices and multiple users reported in-the-wild exploitation that created rogue administrator accounts named 'John Sim' on affected Ubiquiti systems.
Show sources
- Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs — www.securityweek.com — 24.06.2026 15:32
-
08.06.2026 18:51 2 articles · 1mo ago
Bishop Fox validates unauthenticated root RCE chain in UniFi OS Server
Initial DisclosureBishop Fox says CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 can be chained in Ubiquiti UniFi OS Server versions 5.0.6 and earlier to bypass authentication, reach a vulnerable package-update endpoint, and execute commands with root privileges without credentials or user interaction; the researchers also say the flaws were fixed in May, the chain no longer works on UniFi OS Server 5.0.8, and they released a free detection script and hunting guidance for requests to /api/auth/validate-sso/ and ucs/update/latest_package.
Show sources
- Critical UniFi OS bug lets hackers gain root without authentication — www.bleepingcomputer.com — 08.06.2026 18:51
- Critical UniFi OS bug lets hackers gain root without authentication — www.bleepingcomputer.com — 08.06.2026 18:51