Security

Ubiquiti patched 22 UniFi flaws. Someone still has to confirm they landed.

Ubiquiti released Security Advisory Bulletin 067 on August 26, 2026, with 22 UniFi vulnerabilities. Three score 10.0 and can be reached over the network without a login or a click. Patches exist. The open question is whether your consoles, cameras, and phones actually took them. Auto-update helps. It does not replace a person who checks versions and pushes what stalled.

Updated 2026-08-28

What Ubiquiti published this week

On August 26, 2026, Ubiquiti released Security Advisory Bulletin 067. It covers 22 vulnerabilities across the UniFi line. Twenty-one are rated critical. Three carry a CVSS score of 10.0, the top of the scale.

Those three matter because they do not require a stolen password or a user clicking a bad link. An attacker who can reach the device on the network may be able to inject commands or bypass authentication. That is the kind of finding that turns a forgotten NVR or Talk appliance into a foothold.

The bulletin is public. The fixed versions are public. What is not automatic is whether every console, application, and appliance in your office is on those builds.

The three maximum-severity issues, in plain language

CVE-2026-77537 sits in UniFi Protect, the video platform that runs cameras and recorders. Versions 7.1.87 and earlier are affected. Ubiquiti fixed it in Protect 7.2.105. A network attacker with no special privileges can abuse input handling and run commands on the host.

CVE-2026-77550 sits in UniFi OS, the software that runs Dream Machines, Cloud Keys, gateways, NVRs, and self-hosted UniFi OS Server. A CRLF handling flaw can let someone on the network bypass authentication. UniFi OS Server is fixed in 5.1.37. Many hardware families need 5.1.31 or later. NAS and Express models have their own cutoffs. Check the bulletin for your exact model.

CVE-2026-77554 sits in UniFi Talk, the office phone application. Versions 5.2.7 and earlier are affected. The fix is Talk 5.3.2. Same shape as Protect: network access, no login required, command injection on the host.

The rest of the bulletin is not small. Command injection, privilege escalation, and authentication problems also hit UniFi Network, Access, Connect, the UID Enterprise Agent, Protect AI Key, and related appliances. Network Application should be on 10.5.67 or later. Access 4.3.5. Connect 3.24.22. Treat the full product list in SAB-067 as the checklist, not this summary.

This is not the first UniFi scare of 2026

In May, Ubiquiti patched three other maximum-severity UniFi OS flaws (CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910). CISA later added them to the Known Exploited Vulnerabilities catalog. Reporting described botnet activity against internet-reachable consoles.

That history is the point. Vendors ship patches. Attackers scan for the ones nobody installed. A console that was left alone in 2024 is a standing invitation in 2026 if it is reachable and still on an old build.

Ubiquiti has not, as of this writing, said whether the August 26 flaws are already being used in the wild. Low complexity and no user interaction are enough reason to treat them as urgent. Waiting for a headline about your brand of camera is not a plan.

Auto-update on is not the same as patched

Many offices turn on auto-update and stop looking. That setting is useful. It is not a receipt. UniFi is several products on one console. Protect can move while UniFi OS stays put. Talk can sit a release behind. A device can be set to notify instead of apply. A failed download can sit until someone opens the control plane.

We see this on accounts we take over. The checkbox is on. The running version is not the fixed version in the bulletin. Partial updates are how a "we have auto-update" office still shows up in a scan.

Someone still has to compare what is running to what Ubiquiti published, then push anything that stalled. That is the job. The setting is only the start.

Auto-update off is a decision you should make on purpose

Some offices leave auto-update off because a past firmware change caused a blip, or because nobody wants a reboot during the day. That is understandable. It is also how gear ages in place. A console with updates off will not pick up SAB-067. It will sit on the last build someone clicked, sometimes for years.

The danger is quiet. Routing still works. Cameras still record. Phones still ring. Nothing in the front office looks broken. The management interface, if it is reachable, is the part that changed in the attacker’s favor.

If you keep auto-update off, you need a written window and a person who applies vendor builds when a bulletin like this lands. If that person does not exist, turning the setting off is not caution. It is delay with no owner.

How Tailored Tech handles a week like this

When UniFi gear is in scope, we already have the inventory and the versions. A bulletin is a work queue, not a hunt for passwords. We compare each console and application to the fixed builds, take a backup, apply what is due, and confirm the new version after the device comes back.

Auto-update stays useful. We still look. We check that the setting is actually on, that it covers the applications you run, and that the update landed instead of sitting in a pending state. If a build needs a planned window, we schedule it instead of hoping the console picks a quiet hour on its own.

That watch is part of monitoring and maintenance on Starter, Security+, and Complete. It is not a separate product name. The desk already knows the environment, so SAB-067 does not start with "who has the admin login?"

We also treat the extra hygiene that a patch does not replace. Management should not hang on the open internet. Admin accounts should be few, named, and MFA-backed. Unexpected Super Admins get investigated, not ignored.

A short checklist if you run UniFi today

1. List every UniFi console and application: OS version on the hardware, plus Protect, Network, Talk, Access, and Connect if you use them.

2. Compare each one to the fixed versions in Security Advisory Bulletin 067. Do not assume Cloud Key, Dream Machine, NVR, and self-hosted UniFi OS Server share the same number.

3. Confirm whether auto-update is on for each application, not just the console. If a build is pending or failed, push it. Take a backup first.

4. Pull any UniFi management port off the open internet. Use VPN or another controlled path if remote admin is required.

5. Review admin users. Remove stale Super Admins. Turn on MFA.

Official detail lives in Ubiquiti’s Security Advisory Bulletin 067 on the UniFi community releases page. Use that document for model-by-model versions. This article is guidance for owners, not a substitute for the vendor list.

If this gear is already on a Tailored Tech plan

If we manage the environment, this is the work the desk is for. You should not have to become a UniFi release tracker to stay current. If you want a status on your specific consoles, ask. We will tell you what is current, what is pending, and what needs a window.

If you run UniFi yourself and do not have time to verify versions against SAB-067 this week, start a conversation. Bring the model list if you have it. We will map what is urgent and what can wait.

Questions & answers

Questions on this topic

Short answers for buyers comparing options.

Do I need to replace my UniFi hardware?

Usually no. SAB-067 is a software and firmware advisory. Most supported products have a fixed version. Replacement only enters the conversation if a device is out of support and cannot take the build.

Is auto-update enough on its own?

No. Auto-update is a good default. It can miss an application, sit in a failed state, or apply Protect while UniFi OS stays behind. Someone still has to read the running version against the bulletin and push what did not move.

What if we turned auto-update off on purpose?

Then you need a planned window and an owner who applies vendor builds when a critical bulletin lands. Leaving it off with no schedule means the last person who clicked Update is your security timeline.

Were these flaws already used in attacks?

Ubiquiti had not stated that the August 26 issues were exploited in the wild at the time we wrote this. Earlier 2026 UniFi OS flaws were added to CISA’s known-exploited list. Patch on the vendor timeline, not on the news cycle.

How does Tailored Tech watch this for clients?

When UniFi is in scope we document the gear, watch versions, confirm auto-update is doing what you think it is doing, and push stalled builds. That sits inside monitoring and maintenance on Starter, Security+, and Complete. Scope is confirmed during onboarding.

Want this applied to your environment?

Tell us how the business runs. We will map the model without a long pitch.

Start a conversation
Start a conversation