CVE-2026-55116: exploitation status and patch state
CVE-2026-55116 · CVSS 9.0 CRITICAL · EPSS <1%
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.
Is CVE-2026-55116 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at <1%.
Public exploit code: none found in monitored sources.