CVE-2026-54400: exploitation status and patch state
CVE-2026-54400 · CVSS 9.1 CRITICAL · EPSS 1%
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
Is CVE-2026-54400 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 1%.
Public exploit code: none found in monitored sources.