CERT-PY warns on critical Ubiquiti flaws
CERT-PY flagged critical Ubiquiti flaws that could lead to remote code execution, while technical details point to UniFi OS chains.
CERT-PY issued an advisory on critical vulnerabilities in Ubiquiti products that could allow remote code execution. New technical reporting adds a chain of flaws in UniFi OS, including authentication bypass and command injection, broadening the scope to several affected devices and versions.
Update August 26, 2026: CERT-PY's advisory still points to critical vulnerabilities in Ubiquiti, but there is now a possible technical breakdown of the chain in UniFi OS. Outside researchers described three CVEs, two authentication bypasses, and a command injection that could lead to remote code execution with root privileges.
CERT-PY published an advisory on August 13, 2026, about critical vulnerabilities in Ubiquiti products. The regional alert comes alongside an official Ubiquiti advisory on flaws in UniFi OS and the UID Enterprise Agent, while CSIRT Panama issued the same day a critical vulnerability alert tied to PAN-OS.
What did Ubiquiti report about its products?
Ubiquiti published an official advisory covering five vulnerabilities in UniFi OS and the UID Enterprise Agent, including three critical flaws and two rated high. According to the available technical summary, the identifiers are CVE-2026-47367, CVE-2026-47370, CVE-2026-47369, CVE-2026-47368, and CVE-2026-48610.
The available material describes impacts that include command execution, privilege escalation, path traversal, and unauthorized configuration changes. DiaDorn, which summarizes the advisory, not only lists the CVEs and their severity, but also notes that Ubiquiti published CVSS scores for each case.
What do the regional alerts say?
CERT-PY published an advisory on critical-severity vulnerabilities in Ubiquiti products, and the research material indicates that a malicious actor could achieve remote code execution, although the available excerpt does not confirm the exact CVE identifier or whether active exploitation was verified for Paraguay. At the same time, CSIRT Panama issued an alert on PAN-OS with an issue date of August 13, 2026, also classified as critical.
In that case, the Panamanian advisory is linked to CVE-2026-0301, a PAN-OS flaw specifically in URL Filtering, which independent databases such as OpenCVE, CIRCL Vulnerability Lookup, CVEfeed, and GitHub Security Advisory describe as an information disclosure issue.
How is CVE-2026-0301 classified in technical databases?
CVE-2026-0301 is cataloged as an information disclosure flaw that can be exploited by an unauthenticated attacker with network access. According to those databases, it affects specific versions of PAN-OS and Prisma Access.
External technical sources temper the severity compared with the CSIRT Panama advisory. CSIRT labels it low, with a CVSS v4.0 score of 1.7, while aggregated analysis from Esentry and ThreatCluster places it within a broader set of 11 vulnerabilities affecting PAN-OS, GlobalProtect, and Prisma Browser. In that context, the flaw can be useful for infrastructure reconnaissance even if it is not critical on its own.
What is now known about the critical chain in UniFi OS?
Outside security researchers documented a critical vulnerability chain in Ubiquiti UniFi OS that allows unauthenticated remote code execution and escalation to root by chaining at least three flaws: two authentication bypasses, CVE-2026-34908 and CVE-2026-34909, both rated CVSS 10.0, and a command injection in the package update service, CVE-2026-34910, also scored critical.
The independent technical analysis says CVE-2026-34908 is an access-control flaw that lets an unauthenticated attacker reach protected API endpoints by exploiting a mismatch in how the authentication service and routing layer interpret request URLs. Another technical report describes the same unauthenticated remote code execution chain in UniFi OS Server, and says the combination of CVE-2026-34908 and CVE-2026-34909 with CVE-2026-34910 makes it possible to gain root access with a single request and no credentials.
The same analysis lists the scope of affected devices in the UniFi OS vulnerability chain, including UDM Pro, cloud gateways, NVRs, the UNAS lines and Dream Machine Beast, UniFi Express, and devices running UniFi OS Server, each with specific firmware versions that need updating to reduce the risk.
Sources
- Palo Alto Networks Discloses 11 Vulnerabilities Across PAN-OS, GlobalProtect and Prisma Accessesentry.io· Esentry
- CERT-PY – CERT-PYcert.gov.py· CERT-PY
- Palo Alto Networks Addresses Multiple Vulnerabilities in Key Security Productsthreatcluster.io· ThreatCluster
- CVE-2026-0301 - Vulnerability Detailsapp.opencve.io· OpenCVE
- CSIRT Panamá Aviso 2026-ago-13: PAN-OS ...cert.pa· CSIRT Panamá
- CVE-2026-0301 - PAN-OS: Information Disclosure Vulnerability in URL Filteringcvefeed.io· CVEfeed
- Ubiquiti UniFi OS: Critical Security Flaws Patcheddiadorn.de· DiaDorn
- GHSA-69PG-94V9-FCX7 - PAN-OS information disclosure in URL Filteringvulnerability.circl.lu· GitHub Security Advisory
- CVE-2026-0301 - Vulnerability-Lookupvulnerability.circl.lu· CIRCL
- Popping Root on UniFi OS Server: Unauthenticated RCEdaily.dev· daily.dev / Bishop Fox
- UniFi OS Vulnerabilities Found in External Penetration Testunderdefense.com· UnderDefense



