Ubiquiti has shipped fixes for 22 vulnerabilities across its UniFi networking line, 21 of them rated critical and three scoring a perfect 10 on the CVSS scale.
The three maximum-severity bugs, CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554, are improper access control flaws that could let a remote attacker gain elevated privileges on a device or application. Seven of the 22 issues share that root cause. The remaining advisories cover authentication bypass and arbitrary command execution paths; one non-UniFi vulnerability was rated high.
The trio of 10.0 ratings equals the total number of maximum-severity issues Ubiquiti had patched in the entire year before this bulletin: one in March, one in May, and one in July. Two months ago, CISA added three Ubiquiti vulnerabilities to its Known Exploited Vulnerabilities catalog, the agency’s must-patch list.
Ubiquiti released the bulletin without commentary beyond the vulnerability descriptions and recommended mitigations. The company did not respond to questions about whether any of the flaws had been exploited in the wild before the patches shipped.
UniFi gear sits in homes, offices, and campus networks around the world, and access-control bugs of this severity are routinely weaponized quickly. Administrators should prioritize updating controllers, access points, and gateways, and review the bulletin’s mitigation guidance for devices that cannot be patched immediately.
