Ubiquiti released firmware updates for multiple high-severity vulnerabilities in UniFi firewalls and gateway products. Network-accessible attackers could exploit out-of-bounds write, out-of-bounds read, and uncontrolled-recursion flaws to trigger denial-of-service conditions; each issue carries a CVSS score of 7.5. Affected families include Cloud Gateways, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewalls, Express, Express 7, and UniFi Gateways.
Organizations should promptly update affected appliances to the vendor-provided fixed releases. Products running versions earlier than 5.1.31 for Cloud Gateways, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewalls, and Express 7, earlier than 5.1.26 for UniFi Gateways, and earlier than 4.0.21 for Express are affected; administrators should review Ubiquiti's advisory and apply the available firmware updates.

Map this exposure pattern across your cloud, code, and identities.
4 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published Security Advisory Bulletin 069 (AV26-954), identifying affected Ubiquiti product versions and urging administrators to review Ubiquiti's advisory and apply updates.
Ubiquiti Cloud Gateways, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewalls, Express, Express 7, and UniFi Gateways were reported as affected by vulnerabilities.
Some firmware releases fixing the UniFi firewall and gateway vulnerabilities had been available since the prior month.
Ubiquiti disclosed six network-reachable UniFi firewall and gateway vulnerabilities: three out-of-bounds writes, two out-of-bounds reads, and one uncontrolled-recursion issue, each rated CVSS 7.5. Fixed firmware includes version 5.1.31 for several product families, 4.0.21 for UniFi Express, and 5.1.26 for UniFi Gateways.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourceheise.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.