Web_Logo
Remote Support
Security Alert: Ubiquiti Network Devices Added to CISA Exploit List
Home » Security Alerts  »  Security Alert: Ubiquiti Network Devices Added to CISA Exploit List

Security Alert: Ubiquiti Network Devices Added to CISA Exploit List

Three vulnerabilities in Ubiquiti's UniFi OS platform — used in popular business networking equipment — have been confirmed as actively exploited and added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 23 June 2026.

  • What it is: Three separate flaws in Ubiquiti UniFi OS: an improper access control issue (CVE-2026-34908), a path traversal vulnerability (CVE-2026-34909), and an improper input validation flaw (CVE-2026-34910). All three are being actively exploited by attackers.
  • Who is affected: Businesses using Ubiquiti UniFi networking equipment — routers, switches, access points, and gateways running UniFi OS.
  • What the risk is: Attackers who exploit these flaws can gain unauthorised access to your network infrastructure, potentially moving laterally through your environment undetected.
  • What to do: Log into your UniFi Network application or console and apply any pending firmware updates immediately. If updates are not yet available from Ubiquiti, restrict management interface access to trusted IP addresses only until a patch is released.

If your business uses Ubiquiti equipment and you are unsure whether your devices are patched, contact your IT provider for an urgent check.

Source: CISA KEV Catalog Update – 23 June 2026