CERT-PY Warns of Critical Ubiquiti Flaws
CERT-PY issued an alert on critical flaws in Ubiquiti UniFi products affecting multiple devices, apps and network components.
CERT-PY issued an alert on critical-severity vulnerabilities in Ubiquiti UniFi products, affecting several applications, devices and components across the line. The agency points to security updates that address flaws that can affect device state and access to privileged files.
Update September 21, 2026: CERT-PY expanded its advisory on Ubiquiti and tied it to Canadian Centre for Cyber Security advisory AV26-850. The new material also narrows the affected products and versions, and details critical authentication, authorization and hardcoded credential flaws.
CERT-PY has published vulnerability notices for Ubiquiti, Samba, Joomla! and Synology on its official site, including at least one critical-severity flaw and references to security updates that address multiple issues. The agency also recently published a separate advisory on GitLab, with a critical vulnerability that allows arbitrary reading of files accessible to the service account.
What did CERT-PY say about GitLab?
CERT-PY, through an advisory cited by Mallory Security, reported CVE-2026-85706, a directory traversal flaw in the GitLab CE and EE repository commits API. According to that summary, a remote unauthenticated attacker could read arbitrary files accessible to GitLab's service account. The assigned severity is CVSS v3.1 10.0.
The notice fits into a recent run of alerts from the agency about widely used products. In addition to GitLab, CERT-PY has published notices for Ubiquiti, Samba, Joomla! and Synology, with references to security patches for multiple vulnerabilities.
What happened with Ubiquiti?
CERT-PY published an advisory on critical vulnerabilities in Ubiquiti products, and the new material links it to Canadian Centre for Cyber Security advisory AV26-850. The report covers UniFi OS Server, UniFi Network Application, UniFi Protect Application, UniFi Access Application and other UniFi components.
The scope also includes UniFi OS devices such as Dream Machine, Cloud Gateway, Enterprise Fortress, Dream Router, Express and the UNVR line. According to the advisory summary, organizations running those systems should apply updates to fix the flaws.
Which products and versions are affected?
The advisory cited in the new material lists several version limits for UniFi OS Server, UniFi Network Application, UniFi Protect Application and UniFi Access Application. It also names UniFi Connect, UID Enterprise Agent, UniFi Talk, UniFi Protect AI Key, Connect Display Cast Pro and Enterprise Audio/Video Bridge.
| Product | Affected version | Source |
|---|---|---|
| UniFi OS Server | <= 5.1.21 | Canadian Centre for Cyber Security, AV26-850 |
| UniFi Network Application | <= 10.4.57 | Canadian Centre for Cyber Security, AV26-850 |
| UniFi Protect Application | <= 7.1.87 | Canadian Centre for Cyber Security, AV26-850 |
| UniFi Access Application | <= 4.3.3 | Canadian Centre for Cyber Security, AV26-850 |
| UniFi Connect | Not specified in the material | Canadian Centre for Cyber Security, AV26-850 |
| UID Enterprise Agent | Not specified in the material | Canadian Centre for Cyber Security, AV26-850 |
| UniFi Talk | Not specified in the material | Canadian Centre for Cyber Security, AV26-850 |
| UniFi Protect AI Key | Not specified in the material | Canadian Centre for Cyber Security, AV26-850 |
| Connect Display Cast Pro | Not specified in the material | Canadian Centre for Cyber Security, AV26-850 |
| Enterprise Audio/Video Bridge | Not specified in the material | Canadian Centre for Cyber Security, AV26-850 |
What is the technical risk?
Recent CVEs associated with Ubiquiti describe critical authentication bypass and authorization failures in sensitive functions, with CVSS scores from 9.4 to 9.6. Based on the available information, those flaws can be exploited over the network or a nearby network to change device state or access files with elevated privileges.
Another critical CVE tied to Ubiquiti points to hardcoded credentials. When the FTP service is reachable, that condition could allow remote access to files with root privileges.
What happened with the Paraguay alert?
VECERT Analyzer circulated a preventive, unconfirmed alert about the alleged exfiltration and publication of a 10.5 GB database attributed to Paraguay's Ministry of Public Health and Social Welfare. The source itself said the visible evidence has not been verified, so the alleged incident remains unconfirmed independently.
In that same alert, VECERT Analyzer attributed the activity to an actor identified as Zumarius and advised Paraguayan government entities to review database and WAF logs for unusual SQL queries and exfiltration flows of 10 to 15 GB in the previous weeks.
It also recommended blocking the biteblob domain on corporate secure web gateways to stop downloads of the file allegedly linked to the incident. According to the alert, that file could include malware or tracking tools. The advisory also urged rotating service account credentials with access to critical databases and checking that management ports such as 3306 for MySQL and 1433 for MSSQL are not exposed to the internet.
How does the Synology risk look?
The latest reference on Synology softens the immediate risk reading tied to a specific identifier. CVE-2026-87730 is listed as rejected in a reference database that cites security@synology.com and NVD, with no CVSS or EPSS score and no inclusion in CISA's KEV catalog.
That does not contradict CERT-PY's alerts on Synology, but it does show that not every identifier tied to the brand's ecosystem carries the same level of validation or urgency. In this case, the reference database itself marks the CVE as rejected.
Sources
- CVE-2026-87730 – Rejected reasoncyber-defence.io· UK Cyber Defence
- CERT-PY – CERT-PYcert.gov.py· CERT-PY
- VECERT Analyzer on X: "⚠️ TARGETED PREVENTIVE ALERT ...x.com· VECERT Analyzer on X
- CVE-2026-85706 – Unauthenticated Arbitrary File Read in GitLab Repository Commits APImallory.ai· Mallory Security
- Ubiquiti security advisory AV26-850 sobre vulnerabilidades críticas en UniFi OS y aplicaciones asociadaszerohour.day· ZeroHour / Canadian Centre for Cyber Security (referenciado)
- Timeline de Ubiquiti y resumen del impacto de AV26-850 en UniFi OS y dispositivos como Dream Machine, Cloud Gateway y UNVRzerohour.day· ZeroHour
- CVE-2026-66887 – Vulnerabilidad crítica por falta de autorización en funciones de cambio de estado en productos Ubiquiticve.org· CVE.org
- CVE-2026-66890 – Vulnerabilidad crítica por credenciales codificadas con acceso remoto a archivos con privilegios de root en productos Ubiquiticve.org· CVE.org
- Critical Ubiquiti UniFi security flaw allows potential account hijackingsecurityaffairs.com· Security Affairs



