tag
Unauth
CVE-2026-34910, CVE-2026-34909, CVE-2026-34908
network
CRITICAL 10
KEV
EPSS 87%
UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910)
CVE-2026-34910 is an unauthenticated command injection vulnerability in Ubiquiti UniFi OS Server, rated CVSS 10.0 and listed in CISA KEV. The nginx auth layer treats any request whose raw URI starts with /api/auth/validate-sso/ as public, but routes by the…
Patched
2026-08-16