tag
Ubiquiti
CVE-2026-34910, CVE-2026-34909, CVE-2026-34908
network
CRITICAL 10
KEV
EPSS 87%
UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910)
CVE-2026-34910 is an unauthenticated command injection vulnerability in Ubiquiti UniFi OS Server, rated CVSS 10.0 and listed in CISA KEV. The nginx auth layer treats any request whose raw URI starts with /api/auth/validate-sso/ as public, but routes by the…
Patched
2026-08-16
CVE-2026-34908, CVE-2026-34909, CVE-2026-34910
network
CRITICAL 10
KEV
EPSS 62%
Ubiquiti UniFi OS Unauthenticated RCE Chain (CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910)
A three-CVE unauthenticated RCE chain in Ubiquiti UniFi OS Server ≤ 5.0.6 allows a remote attacker to achieve root-level command execution with no credentials. CVE-2026-34908 and CVE-2026-34909 (improper access control + path traversal) are chained to bypass…
Patched
2026-06-28