Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

UniFi OS CVSS 10 Trio Exploited: CVE-2026-34908, 34909, 34910 (UDM, Cloud Key, UNVR, UNAS)

Critical CVE-2026-34908, CVE-2026-34909, CVE-2026-34910 — Three maximum-severity UniFi OS bugs (access control, path traversal, command injection) are being exploited. Affects Dream Machines, Cloud Gateways, Cloud Keys, NVRs and UNAS. Fixed in UniFi OS 5.1.12 / 5.1.10 / 5.0.8.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: Anyone who can reach a UniFi OS console on the network can change its settings, read files to take over an account, or inject commands. All three are rated CVSS 10.0 and are on CISA's exploited list. Update UniFi OS to 5.1.12 or later (UNAS: 5.1.10, Express: 4.0.14, UniFi OS Server: 5.0.8), and keep the console's management interface off the internet and off guest/IoT networks.

CVE-2026-34908Improper access control → unauthorized system changes. CVSS 10.0
CVE-2026-34909Path traversal → read files, take over an underlying account. CVSS 10.0
CVE-2026-34910Input validation → command injection. CVSS 10.0
Attacker needsNetwork access to the console. No credentials are mentioned in the advisory.
AffectedUDM, UDM-Pro/SE/Pro-Max/Beast, UDR/UDR7/UDR-5G, UDW, UCG-Ultra/Max/Fiber/Industrial, UCK/UCK G2+/Enterprise, UNVR family, ENVR, EFG, Express, UNAS, UniFi OS Server
Fixed inUniFi OS 5.1.12 (most consoles; UDM-Beast 5.1.11; UNAS 5.1.10), Express 4.0.14, UniFi OS Server 5.0.8
Exploited?Yes, CISA KEV 2026-06-23

What the bugs are

UniFi OS is the operating system on Ubiquiti’s consoles: the Dream Machine routers, Cloud Gateways, Cloud Keys, NVRs and the UNAS storage boxes. Ubiquiti’s Security Advisory Bulletin 064 fixed three flaws that each score the maximum 10.0:

  • CVE-2026-34908: improper access control lets someone with network access make unauthorized changes to the system.
  • CVE-2026-34909: path traversal lets them read files on the underlying system and use them to access an account.
  • CVE-2026-34910: improper input validation leads to command injection.

Because these consoles are usually the router and the controller for every switch, access point and camera on the network, owning one means owning the whole network.

Am I affected?

In the UniFi web interface go to Settings → Control Plane → Updates (or the console’s overview page) and look at the UniFi OS version. Over SSH: cat /usr/lib/version or ubnt-device-info firmware.

DevicePatched at
Dream Machine (UDM, Pro, SE, Pro Max), Dream Router (UDR, UDR7, UDR-5G), Dream Wall, Cloud Gateways (Ultra, Max, Fiber, Industrial), Cloud Keys, UNVR / ENVR family, EFG, Express 75.1.12
UDM-Beast5.1.11
UNAS 2 / 4 / Pro / Pro 4 / Pro 85.1.10
UniFi Express4.0.14
UniFi OS Server (self-hosted)5.0.8

This is UniFi OS, the console operating system, not the UniFi Network application version. Check the right number.

How to patch

  1. Settings → Control Plane → Updates → update UniFi OS. Expect a few minutes of downtime; on a gateway, the internet drops during the reboot.
  2. Turn on automatic UniFi OS updates there, ideally with a nightly maintenance window.
  3. Make sure the console itself has a current backup (Settings → Control Plane → Backups) before and after.

Hardening

  • Don’t forward ports to the console’s management UI. Use UniFi’s remote access or a VPN (WireGuard/Teleport on the gateway) instead.
  • Keep guest and IoT networks isolated from the management VLAN (enable Network Isolation / firewall rules so those networks can’t reach the gateway’s UI). “Network access” in these CVEs includes your own LAN.
  • Disable SSH on the console unless you use it, and set a strong unique SSH password if you do.

Signs of compromise

  • Admins you didn’t add (Settings → Admins & Users), changed port forwards, new VPN clients, or DNS settings pointing somewhere unfamiliar.
  • Unexpected outbound traffic from the console itself.
  • If in doubt: back up the config, factory reset, update, restore, and rotate all admin passwords and Wi-Fi keys.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories