CERT-PY flags critical Ubiquiti flaws
CERT-PY warned about critical Ubiquiti flaws and said Samba patches are already available. Ubiquiti fixed 22 UniFi vulnerabilities.
CERT-PY issued an alert on critical vulnerabilities in Ubiquiti products that could allow remote code execution, while also reporting security updates for multiple Samba flaws. In Ubiquiti’s case, the focus is on 22 vulnerabilities in the UniFi platform, including three critical issues that now have published patches.
CERT-PY issued an alert about critical-severity vulnerabilities in Ubiquiti products that could let an attacker achieve remote code execution. At the same time, it said security updates are already available to fix multiple Samba vulnerabilities. The Paraguayan agency did not specify the affected products in its local notice, but the technical material available points most strongly to the UniFi platform.
What did Ubiquiti say about UniFi?
Ubiquiti published Security Advisory Bulletin 067 on August 26, 2026, and detailed 22 vulnerabilities in the UniFi platform, including three critical issues rated CVSS 10.0 that affect UniFi Protect, UniFi OS Server, and UniFi Talk. According to the technical summaries cited, the critical flaws are tied to CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554.
Mallory.ai describes CVE-2026-77537 as a command injection issue in the UniFi Protect Application, CVE-2026-77550 as a CRLF injection that enables authentication bypass in UniFi OS, and CVE-2026-77554 as a command injection issue in the UniFi Talk Application. The same source says the three vulnerabilities allow remote exploitation without authentication, with low complexity and no user interaction.
Ubiquiti has released specific patches for those flaws. According to Mallory.ai, UniFi Protect Application is fixed in version 7.2.105 and later, UniFi OS Server fixes the CRLF injection issue in branch 5.1.21 and later, and UniFi Talk Application is fixed starting with version 5.3.2.
What scope did other response teams report?
The Canadian Centre for Cyber Security, in advisory AV26-850 dated August 26, 2026, warned that multiple UniFi products are affected by the vulnerabilities described in Ubiquiti’s bulletin and urged immediate installation of the relevant updates. The products named include UniFi OS Server, UniFi Network, UniFi Protect, UniFi Access, UniFi Talk, and specialized devices such as UniFi Protect AI Key.
The Canadian advisory also states that UniFi Protect AI Key is affected in all versions earlier than 2.1.3, extending the exposure beyond the main controllers to peripheral video surveillance equipment. CERT.LV also issued a specific notice for Ubiquiti users, summarizing the risks in CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554 and noting that they can allow arbitrary commands or bypass authentication mechanisms on UniFi Protect, UniFi OS, and UniFi Talk devices.
OpenCVE, meanwhile, describes CVE-2026-77554 in UniFi Talk Application as an input validation flaw that allows command injection and remote code execution, with a CVSS score of 10.0. SCWorld also covered the release of patches for these three critical vulnerabilities and noted that attacks can be launched remotely and without privileges.
What about Samba?
CERT-PY also said security updates are available for Samba and that they fix multiple vulnerabilities. Supporting material from the Samba project, cited by the technical summaries, says the patches cover privilege escalation and remote code execution flaws in file server configurations used as domain controllers.
That exposure is especially relevant for corporate and government infrastructures that rely on Samba instead of proprietary Active Directory. On that front, the operational guidance in the Paraguayan alert is to apply the updates released by the project.
What other Ubiquiti products came under review?
Beyond the UniFi line, Ubiquiti’s exposure map also includes EdgeMAX EdgeSwitch. CVEfeed.io says CVE-2026-77532, a buffer overflow in DHCPv6, allows remote code execution from an adjacent network. Bishop Fox, via Daily.dev, also published a technical analysis of UniFi OS Server that describes an unauthenticated RCE exploitation chain and says the fix is introduced in UniFi OS Server 5.0.8, leaving versions 5.0.6 and earlier exposed.
Taken together, the alerts from CERT-PY, Ubiquiti’s bulletin, and notices from international response organizations point to one immediate step, applying the patches already available for UniFi and Samba.
Sources
- CVE-2026-77554 - Vulnerability Detailsapp.opencve.io· OpenCVE
- CVE-2026-77532 - Ubiquiti EdgeMAX EdgeSwitch Buffer Overflowcvefeed.io· CVEfeed.io
- Brīdinājums Ubiquiti iekārtu lietotājiemcert.lv· CERT.LV
- Popping Root on UniFi OS Server: Unauthenticated RCEdaily.dev· Bishop Fox (via Daily.dev)
- Ubiquiti Patches Three Simultaneous Maximum-Severity UniFi Flaws in Cameras, OS, and VoIPtechtimes.com· TechTimes
- Samba Security Advisoriessamba.org· Samba Project
- CERT-PY – CERT-PYcert.gov.py· CERT-PY
- Ubiquiti patches 3 critical remote code execution vulnerabilitiesscworld.com· SCWorld
- Ubiquiti Patches Three Critical Remote Flaws in UniFi Productsmallory.ai· Mallory.ai
- UniFi OS CRLF Injection Authentication Bypass (CVE-2026-77550)mallory.ai· Mallory.ai
- Ubiquiti security advisory (AV26-850)cyber.gc.ca· Canadian Centre for Cyber Security
- Bulletin de sécurité Ubiquiti (AV26-850)cyber.gc.ca· Canadian Centre for Cyber Security



