Ubiquiti released Security Advisory Bulletin 065 to address five vulnerabilities in UniFi OS, including critical path traversal (CVE-2026-47368), privilege escalation (CVE-2026-47369), and command injection (CVE-2026-47370) flaws that affect a wide range of consoles, gateways, servers, NVRs, NAS devices, Dream Machines, Cloud Keys, and Express products. The advisory says a network-adjacent attacker could abuse the bugs to read arbitrary files, escalate privileges, execute commands, and in some cases make unauthorized configuration changes through CVE-2026-48610, with several issues rated as high as CVSS 9.9.
Ubiquiti warned that the vulnerabilities can be chained, allowing attackers to remove privilege requirements and potentially reach full device compromise, echoing broader concern over repeated severe UniFi OS weaknesses. Firmware updates were issued with fixes in UniFi OS 5.1.15 for most affected families, 5.1.16 for UNAS devices, and 4.0.15 for Express appliances; security reporting around the bulletin also urged organizations to patch all listed CVEs together and treat previously exposed, unpatched management interfaces as potentially compromised.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Ubiquiti released patches for the Bulletin 065 vulnerabilities on June 10, 2026. Most affected UniFi OS families were fixed in version 5.1.15, with UNAS devices requiring 5.1.16 and Express devices 4.0.15.
Ubiquiti disclosed Security Advisory Bulletin 065 covering five vulnerabilities in UniFi OS, including CVE-2026-47368, CVE-2026-47369, CVE-2026-47370, and CVE-2026-48610. The bulletin warned that some of the flaws could be chained to increase impact up to full device compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
zeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcereddit.com
Open sourcecommunity.ui.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.