Ubiquiti released Security Advisory Bulletin 064 to fix five vulnerabilities in UniFi OS, including three unauthenticated remote code execution flaws tracked as CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, each described by community reporting as CVSS 10.0 issues affecting a broad range of UDM, UCG, and UNVR devices. The advisory also addressed CVE-2026-33000, a CVSS 9.1 command injection vulnerability in UniFi OS Server that can let an attacker with administrative privileges and network access execute arbitrary operating system commands and potentially gain root-level control over managed infrastructure.
The command injection bug was reported through HackerOne by researcher V3rlust, and Ubiquiti said UniFi OS Server 5.0.8 and later contain the fix, while 5.0.6 and earlier are confirmed vulnerable. Public reporting noted that roughly 87,196 exposed UniFi Network Application hosts were visible from the internet, raising concern that the unauthenticated RCE flaws could be chained with the command injection issue to compromise internet-facing deployments; administrators were urged to update firmware immediately, restrict management-plane exposure, and verify patch status across deployed systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
At the time of the disclosure analysis, Censys observed 87,196 exposed UniFi Network Application hosts, indicating substantial potential exposure. The source does not explicitly anchor this observation to a specific event date.
On 2026-05-21, Ubiquiti disclosed Security Advisory Bulletin 064 covering five vulnerabilities, including CVE-2026-33000 and three unauthenticated RCE flaws tracked as CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910. The advisory states CVE-2026-33000 was patched in UniFi OS Server version 5.0.8 and later, while version 5.0.6 and earlier were confirmed vulnerable.
The command injection vulnerability CVE-2026-33000 in UniFi OS Server was reported to Ubiquiti by researcher V3rlust through HackerOne. The source does not provide a specific date for the report.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
zeropath.com
Open sourcereddit.com
Open sourcereddit.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.