Cyber Security News

CISA Warns of Ubiquiti UniFi OS Vulnerability Actively Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added multiple Ubiquiti UniFi OS vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, warning that at least one of the flaws is now being actively exploited in the wild.

Federal civilian agencies and other UniFi deployments are urged to prioritize patching by June 26, 2026, in line with CISA’s Binding Operational Directive (BOD) 26-04.

According to the advisory, the most critical issue, tracked as CVE-2026-34908, stems from improper access control in Ubiquiti UniFi OS. An attacker with network access can make unauthorized changes to the system, potentially altering configurations, disabling security controls, or manipulating network behavior within affected environments.

CISA notes that stakeholders must assess each asset’s internet exposure and ensure updates are prioritized based on risk, especially where UniFi management interfaces are reachable from untrusted networks.

CISA also flagged two additional UniFi OS flaws that could be chained with the access control issue for deeper compromise. CVE-2026-34909 is a path traversal vulnerability that allows an authenticated or local attacker with network access to read or manipulate files on the underlying system, which could then be abused to gain access to an underlying account.

CVE-2026-34910, an improper input validation bug, enables command injection, giving an attacker the ability to execute arbitrary commands on the device once a foothold is established.

While there is currently no confirmed evidence that these specific UniFi OS flaws are being used in ransomware campaigns, CISA has classified the exploitation status as “unknown” and warns that the access gained through these issues aligns with common ransomware operator tradecraft.

Once a UniFi controller or gateway is compromised, threat actors could pivot into internal networks, harvest credentials, or tamper with traffic flows to support data theft, lateral movement, or disruptive attacks.

CISA directs organizations to apply mitigations in accordance with Ubiquiti’s vendor guidance and to align actions with BOD 26-04’s risk-based patching requirements and CISA’s Forensics Triage Requirements.

For cloud-hosted UniFi deployments, agencies must follow the portions of BOD 26-04 that specifically address cloud services or discontinue use of the product if mitigations or patches are not available in time.

Operators are reminded that they are responsible for evaluating exposure, ensuring accelerated patching of internet-facing systems, and maintaining logs to support rapid forensic triage in the event of suspected exploitation.

Download Free Microsoft Vulnerabilities Report 2026
– A The latest Microsoft Vulnerabilities data, analyzed.

Download Now
Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago