Ubiquiti Ships Broad Fixes Across UniFi and EdgeMAX

Ubiquiti released security updates for 23 vulnerabilities across UniFi and EdgeMAX products, including 22 marked critical and one high, affecting controller software and appliance firmware in the same advisory wave. CSIRT Italia said the fixes cover UniFi Protect, UniFi OS, Network, Access, Connect and Talk, UID Enterprise Agent, and EdgeMAX EdgeSwitch, while BleepingComputer highlighted three maximum-severity remote bugs. The issues can allow authentication bypass, arbitrary code execution, or privilege escalation. In plain terms, that means an attacker who reaches the right service may be able to skip login, run commands, or take over higher-privilege functions on the device, depending on the product and flaw. For operators, the important part is the patch scope: some exposure lives in management applications and some in embedded devices, so a clean-looking controller does not guarantee the appliance side is current. If your environment uses multiple Ubiquiti layers, the remaining risk sits wherever one layer updates and the other does not.

Part of the PlainSec briefing for 2026-08-26

Editions

Sources