Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-77537: UniFi Protect lets network attacker run commands

CVE-2026-77537 · published 8 days ago
Summary

The UniFi Protect software does not properly check data it receives from the network. An attacker who can reach the network can trick it into executing commands on the server, potentially taking control of the system. Apply the latest vendor update or restrict network access to the application to mitigate the risk.

What to do
  • Update ubiquiti inc unifi protect application to version 7.2.105 or later.
Affected software
VendorProductAffected versions
ubiquiti inc unifi protect application < 7.2.105
Original advisory text
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
Severity
10.0 Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-20Improper Input Validation
Timeline
Published26 Aug 2026
Updated30 Aug 2026
First seen26 Aug 2026
Sources
CVE-2026-77537 · MITRE
Monitor software like this
Free during beta