CVE-2026-77535
Ubiquiti UniFi vulnerability analysis and mitigation

Overview

CVE-2026-77535 is an Improper Input Validation vulnerability in Ubiquiti's UniFi Network Application that enables command injection on adopted network devices. A malicious actor with high privileges and network access can exploit this flaw to execute arbitrary commands on devices managed by the application. All versions of UniFi Network Application prior to 10.5.67 are affected. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical), assigned by Ubiquiti, and was published on August 26, 2026 (Ubiquiti Advisory, EUVD).

Technical details

The root cause is classified as CWE-20 (Improper Input Validation), where user-supplied input is not adequately sanitized before being passed to system-level command execution routines within the UniFi Network Application. An attacker with high privileges (e.g., administrator-level access) can craft malicious input over the network that triggers command injection on an adopted UniFi device — a device managed and provisioned through the application. The attack vector is network-based, requires no user interaction, and the scope is changed, meaning the impact extends beyond the application itself to the underlying adopted devices (Ubiquiti Advisory, EUVD).

Impact

Successful exploitation grants an attacker complete control over adopted UniFi devices, with high impact to confidentiality, integrity, and availability. An attacker can execute arbitrary commands on managed devices, potentially exfiltrating sensitive configuration data, modifying device behavior, disrupting network operations, or using compromised devices as pivot points for lateral movement within the network. The changed scope means the impact propagates beyond the UniFi Network Application itself to all devices under its management (Ubiquiti Advisory, GBHackers).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The CVE status is listed as "Deferred" and the NVD SSVC assessment indicates exploitation is "none" and the vulnerability is not automatable, as it requires high privileges to exploit. The EPSS score is approximately 0.0081 (0.81%), reflecting a low near-term exploitation probability. CVE-2026-77535 is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (EUVD).

Mitigation and workarounds

Ubiquiti has addressed this vulnerability in UniFi Network Application version 10.5.67 and later; administrators should upgrade immediately (Ubiquiti Advisory). As interim mitigations, restrict network access to the UniFi Network Application to trusted administrators only, implement network segmentation to limit exposure, and apply the principle of least privilege to administrative accounts. Monitor application logs for anomalous command execution patterns or unexpected configuration changes on adopted devices (GBHackers).

Community reactions

The vulnerability was disclosed as part of a broader Ubiquiti security advisory (Bulletin 067) addressing 22 UniFi flaws, including three rated at CVSS 10.0, which drew significant media attention (Ubiquiti Advisory). Security news outlets including CyberSecurityNews, GBHackers, and TechTimes covered the batch disclosure, highlighting the severity of the overall advisory and Ubiquiti's remediation effort (CyberSecurityNews, GBHackers, TechTimes). Community reaction focused on the breadth of the advisory rather than this specific CVE, with no notable individual researcher commentary identified for CVE-2026-77535.

Additional resources


SourceThis report was generated using AI

Related Ubiquiti UniFi vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77541CRITICAL9.1
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesAug 26, 2026
CVE-2026-77535CRITICAL9.1
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesAug 26, 2026
CVE-2026-55114HIGH8.8
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026
CVE-2026-55118HIGH8.3
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026
CVE-2026-56842HIGH7.5
  • Ubiquiti UniFi logoUbiquiti UniFi
  • cpe:2.3:a:ui:unifi_network_application
NoYesJul 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management