Ubiquiti released patches for two vulnerabilities in the UniFi Network Application (also known as the UniFi Controller), including CVE-2026-22557, a critical path traversal flaw rated CVSS 10.0. The vulnerability could allow an unauthenticated attacker with network access to read files from the target system and potentially compromise accounts without user interaction. A second issue, CVE-2026-22558, is an authenticated NoSQL injection vulnerability that could be used for privilege escalation.
Affected versions include UniFi Network Application 10.1.85 and earlier, release candidate 10.2.93 and earlier, and UniFi Express builds running 9.0.114 and earlier. Ubiquiti said the issues are fixed in UniFi Network Application 10.1.89 or later, 10.2.97 or later for the release candidate, and UniFi Express firmware 4.0.13 or later with UniFi Network Application 9.0.118 or later. Singapore's Cyber Security Agency urged administrators to update to the latest version immediately.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Ubiquiti disclosed and fixed two vulnerabilities in the UniFi Network Application: CVE-2026-22557, a critical path traversal flaw, and CVE-2026-22558, an authenticated NoSQL injection privilege-escalation issue. Recommended fixed versions included UniFi Network Application 10.1.89 or later, 10.2.97 or later for the release candidate, and UniFi Express firmware 4.0.13 or later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
csa.gov.sg
Open sourcetruesec.com
Open sourcecensys.com
Open sourcecommunity.ui.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.