Find notable cyber news and cases, enriched with sources, timelines, and signals.

UniFi OS Server unauthenticated root RCE chain (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 25
2 unique sources, 2 articles

Summary

Hide ▲

UniFi OS Server is exposed to an unauthenticated root RCE chain that combines CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, putting versions 5.0.6 and earlier at risk. Researchers validated the chain on a live 5.0.6 instance and showed that it can reach root without credentials or user interaction. The flaws were fixed in May, and defenders can confirm exposure with a free detection script before upgrading to 5.0.8 or later.

Related Happenings

F5 BIG-IP APM active exploitation wave (CVE-2025-53521)

Exploitation Wave
H score79 First: 02.04.2026 11:25 Last: 02.04.2026 11:25 Sources 1

About this happening: As of 2026-04-02, ongoing attacks are exploiting CVE-2025-53521 against F5 BIG-IP APM systems, leaving more than 14,000 exposed online and at risk of remote code e...

CISA KEV patch order for Dell RecoverPoint

Public Sector Action
H score36 First: 19.02.2026 17:30 Last: 19.02.2026 17:30 Sources 1

About this happening: CISA added CVE-2026-22769 to the KEV catalog and ordered Federal Civilian Executive Branch agencies to secure their networks by February 21. The directive unde...

UNC6201 Dell RecoverPoint for Virtual Machines zero-day campaign

Campaign
H score44 First: 17.02.2026 22:15 Last: 17.02.2026 22:15 Sources 1

About this happening: The UNC6201 campaign has been exploiting a Dell zero-day since mid-2024, creating a sustained risk of unauthorized access and stealthy movement across victims' virtual...

Latest development: 19.02.2026 17:30

CISA added CVE-2026-22769 to its Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to secure affected Dell RecoverPoint systems by Saturday, February 21, after Mandiant and Google Threat Intelligence Group (GTIG) said UNC6201 had exploited the flaw since at least mid-2024.

BeyondTrust Remote Support and Privileged Remote Access CVE-2026-1731 active exploitation wave

Exploitation Wave
H score76 First: 12.02.2026 23:34 Last: 12.02.2026 23:34 Sources 1

About this happening: CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access is now seeing first in-the-wild exploitation, putting exposed appliances at risk of remote...

CISA adds three exploited vulnerabilities to KEV with federal remediation deadline

Public Sector Action
H score35 First: 15.10.2025 12:23 Last: 15.10.2025 12:23 Sources 1

About this happening: CISA added three exploited vulnerabilities to the KEV catalog, requiring federal agencies to apply the patches by November 4, 2025. The action turns already ex...

Timeline

  1. 24.06.2026 15:32 1 articles · 21d ago

    CISA adds UniFi OS Server CVEs to KEV after in-the-wild exploitation reports

    Exploitation Observed

    CISA added CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 to the Known Exploited Vulnerabilities (KEV) catalog after warnings that threat actors were targeting UniFi OS Server devices and multiple users reported in-the-wild exploitation that created rogue administrator accounts named 'John Sim' on affected Ubiquiti systems.

    Show sources
  2. 08.06.2026 18:51 2 articles · 1mo ago

    Bishop Fox validates unauthenticated root RCE chain in UniFi OS Server

    Initial Disclosure

    Bishop Fox says CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 can be chained in Ubiquiti UniFi OS Server versions 5.0.6 and earlier to bypass authentication, reach a vulnerable package-update endpoint, and execute commands with root privileges without credentials or user interaction; the researchers also say the flaws were fixed in May, the chain no longer works on UniFi OS Server 5.0.8, and they released a free detection script and hunting guidance for requests to /api/auth/validate-sso/ and ucs/update/latest_package.

    Show sources