Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic with red warning elements on dark navy background for Ubiquiti UniFi vulnerability advisory

Three More Max-Severity UniFi Flaws — Update Your Ubiquiti Gear Now

Ubiquiti has patched three new maximum-severity vulnerabilities in its UniFi platform — all exploitable remotely by unauthenticated attackers. If your business runs UniFi networking, cameras, or phone systems, check your firmware today.

The three flaws, disclosed by BleepingComputer on 26 August, affect different parts of the UniFi ecosystem:

  • CVE-2026-77537 — an input validation flaw in UniFi Protect (Ubiquiti’s camera and surveillance platform) that lets unauthenticated attackers compromise unpatched devices.
  • CVE-2026-77550 — a CRLF injection bug in UniFi OS that bypasses authentication entirely. Any device running UniFi OS is affected.
  • CVE-2026-77554 — a command injection flaw in UniFi Talk, Ubiquiti’s VoIP phone system.

All three are rated maximum severity and require no authentication or user interaction to exploit.

Why This Matters for Australian Businesses

UniFi is arguably the most common networking platform in Australian SMB environments. It’s affordable, capable, and widely deployed by MSPs and business owners alike. That popularity also means a large attack surface — Censys tracks over 100,000 UniFi OS instances exposed to the internet globally.

This is the second batch of max-severity UniFi patches in two months. In June, CISA ordered federal agencies to patch three similar flaws within three days after they were actively exploited in the wild. Many Australian businesses with self-managed UniFi setups didn’t hear about that until well after exploitation had started — because nobody was watching.

What to Do

Update to UniFi Protect Application 7.2.105 or later, UniFi Talk Application 5.3.2 or later, and UniFi OS 5.1.21 or later. If you’re not sure what firmware you’re running, that’s the first problem to solve — check your UniFi controller dashboard today.

If your UniFi gear is managed by an MSP, confirm they’ve applied the patches. If it’s self-managed, this is a good reminder that networking gear needs the same patch discipline as your servers and workstations.

Need help checking your UniFi environment? Get in touch with All IT Services — we manage UniFi deployments across Sydney, the Central West, Brisbane, and Melbourne.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →