Partial UniFi Patching Leaves the Stack Exposed

UniFi appliances do not become safe just because the host OS is updated. Ubiquiti split fixes across UniFi OS and the bundled apps, so leaving any one layer behind can still leave a command injection or privilege-escalation path on the same device. The new advisory covers 25 UniFi flaws across UniFi OS, Connect, Talk, Access, and Protect. That includes seven critical bugs in UniFi OS and six CVEs CISA already marked as overdue KEV items, with fixes landing in UniFi Connect 3.4.20, UniFi Talk 5.2.2, UniFi Access 4.2.29, UniFi Protect 7.1.83, and UniFi OS 5.1.19. The practical risk is a shared appliance stack where one exposed app can still hand an attacker control even after another layer is patched. For teams running UniFi management gear, the target is the whole stack, not a single product name.

Part of the PlainSec briefing for 2026-07-09

Sources