Ubiquiti Fixes UniFi Control-Plane Flaws Across the Fleet

Ubiquiti and CSIRT Italia said 23 UniFi vulnerabilities are now fixed, including three CVSS 10.0 flaws, with affected versions listed across controllers, gateways, recorders, storage, access, talk, connect, and EdgeMAX EdgeSwitch devices. The common thread is improper access control: some flaws can let an attacker bypass authentication, run arbitrary code, or raise privileges on the device they reach. In UniFi, that matters because the management layer is the control plane for other hardware, so a hit to one appliance can expose the devices it administers as well. For operators with UniFi gear in production, the exposure is not a single box but the management estate behind it. What remains after patching depends on which controller or appliance sits at the center of that estate, and whether any downstream devices inherited trust from it.

Part of the PlainSec briefing for 2026-08-26

Editions

Sources