CERT-PY flags critical Ubiquiti flaws
CERT-PY issued an alert on critical Ubiquiti flaws, while CSIRT Panama also warned about a PAN-OS issue on August 13, 2026.
CERT-PY issued an advisory on August 13, 2026, about critical vulnerabilities in Ubiquiti products, while CSIRT Panama released a similar alert on PAN-OS the same day. Ubiquiti also detailed five flaws in UniFi OS and the UID Enterprise Agent, and independent vulnerability databases listed CVE-2026-0301 as an information disclosure flaw in PAN-OS.
CERT-PY issued an advisory on August 13, 2026, about critical vulnerabilities in Ubiquiti products. The regional alert adds to an official Ubiquiti advisory on flaws in UniFi OS and the UID Enterprise Agent, while CSIRT Panama also published a critical vulnerability alert tied to PAN-OS that same day.
What did Ubiquiti report about its products?
Ubiquiti published an official advisory on five vulnerabilities in UniFi OS and the UID Enterprise Agent, including three critical issues and two high-risk ones. According to the available technical summary, the identifiers are CVE-2026-47367, CVE-2026-47370, CVE-2026-47369, CVE-2026-47368, and CVE-2026-48610.
The available material describes impacts that include command execution, privilege escalation, path traversal, and unauthorized configuration changes. DiaDorn, which summarizes the advisory, not only lists the CVEs and their severity, but also notes that Ubiquiti published CVSS scores for each case.
What appears in the regional alerts?
CERT-PY published an advisory on critical vulnerabilities in Ubiquiti products, but the research material in this batch does not include additional verifiable technical detail from the Paraguayan bulletin. At the same time, CSIRT Panama issued an alert on PAN-OS dated August 13, 2026, also classified as a critical vulnerability.
In that case, the Panamanian notice is linked to CVE-2026-0301, a PAN-OS flaw specifically in URL Filtering that independent databases such as OpenCVE, CIRCL Vulnerability Lookup, CVEfeed, and GitHub Security Advisory describe as an information disclosure issue.
How is CVE-2026-0301 classified by technical databases?
CVE-2026-0301 is classified as an information disclosure flaw that can be exploited by an unauthenticated attacker with network access. According to those databases, it affects specific versions of PAN-OS and Prisma Access.
External technical sources qualify the severity differently than CSIRT Panama's advisory. CSIRT labels it as low severity, with a CVSS v4.0 score of 1.7, while aggregated analyses from Esentry and ThreatCluster place it within a broader set of 11 vulnerabilities affecting PAN-OS, GlobalProtect, and Prisma Browser. In that context, the flaw may help with infrastructure reconnaissance, even if it is not critical on its own.
Sources
- Palo Alto Networks Discloses 11 Vulnerabilities Across PAN-OS, GlobalProtect and Prisma Accessesentry.io· Esentry
- CERT-PY – CERT-PYcert.gov.py· CERT-PY
- Palo Alto Networks Addresses Multiple Vulnerabilities in Key Security Productsthreatcluster.io· ThreatCluster
- CVE-2026-0301 - Vulnerability Detailsapp.opencve.io· OpenCVE
- CSIRT Panamá Aviso 2026-ago-13: PAN-OS ...cert.pa· CSIRT Panamá
- CVE-2026-0301 - PAN-OS: Information Disclosure Vulnerability in URL Filteringcvefeed.io· CVEfeed
- Ubiquiti UniFi OS: Critical Security Flaws Patcheddiadorn.de· DiaDorn
- GHSA-69PG-94V9-FCX7 - PAN-OS information disclosure in URL Filteringvulnerability.circl.lu· GitHub Security Advisory
- CVE-2026-0301 - Vulnerability-Lookupvulnerability.circl.lu· CIRCL



