CiberLATAMbywhalemate

CERT-PY expands Ubiquiti alert over flaws

CERT-PY expanded its Ubiquiti advisory with affected products, versions and remote code execution risks tied to UniFi OS flaws.

Whalemate Labs · AI-assisted researchPublished:Updated 5 min read

CERT-PY expanded its Ubiquiti advisory and linked it to reports of active exploitation of several critical UniFi OS flaws. The alert now covers more products and versions, including gateways, Dream Machines, Dream Routers and other UniFi devices.

Update September 24, 2026: CERT-PY expanded its advisory on Ubiquiti and tied it to reports of active exploitation of several critical UniFi OS flaws. The new coverage adds more products, affected versions and details of a public exploit for a command injection flaw in UniFi OS Server.

CERT-PY has published vulnerability advisories on Ubiquiti, Samba, Joomla! and Synology on its official site, including at least one critical-severity flaw and references to security updates that address multiple issues. In parallel, the agency also recently issued a separate advisory on GitLab, with a critical vulnerability that allows arbitrary reading of files accessible to the service account.

What did CERT-PY say about GitLab?

CERT-PY, through an advisory cited by Mallory Security, reported CVE-2026-85706, a directory traversal flaw in GitLab CE and EE’s repository commits API. According to that summary, a remote unauthenticated attacker could read arbitrary files accessible to GitLab’s service account. The assigned severity is CVSS v3.1 10.0.

The notice fits into a string of recent alerts from the agency on widely used products. Beyond GitLab, CERT-PY also issued advisories for Ubiquiti, Samba, Joomla! and Synology, with references to security patches that fix multiple vulnerabilities.

What happened with Ubiquiti?

CERT-PY published an advisory on critical vulnerabilities in Ubiquiti products, and the updated material links it to Canadian Centre for Cyber Security advisory AV26-850. That report covers UniFi OS Server, UniFi Network Application, UniFi Protect Application, UniFi Access Application and other components in the UniFi line.

Media outlets and security firms have also reported active exploitation, or attempts to chain, the Ubiquiti vulnerabilities CVE-2026-34908, CVE-2026-34909 and CVE-2026-34910 in UniFi OS to achieve remote code execution. According to those reports, CISA has considered these flaws actively exploited since late June 2026.

The scope also includes UniFi OS devices such as Dream Machine, Cloud Gateway, Enterprise Fortress, Dream Router, Express and the UNVR line. The latest material also adds UniFi Gateway, Cloud Gateways, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewalls, Express and Express 7 among the product families covered by the patches.

What products and versions are affected?

The advisory cited in the new material lists several cutoff versions for UniFi OS Server, UniFi Network Application, UniFi Protect Application and UniFi Access Application. It also names UniFi Connect, UID Enterprise Agent, UniFi Talk, UniFi Protect AI Key, Connect Display Cast Pro and Enterprise Audio/Video Bridge.

Product Affected version Source
UniFi OS Server ≤ 5.1.21 Canadian Centre for Cyber Security, AV26-850
UniFi Network Application ≤ 10.4.57 Canadian Centre for Cyber Security, AV26-850
UniFi Protect Application ≤ 7.1.87 Canadian Centre for Cyber Security, AV26-850
UniFi Access Application ≤ 4.3.3 Canadian Centre for Cyber Security, AV26-850
UniFi Connect Not specified in the material Canadian Centre for Cyber Security, AV26-850
UID Enterprise Agent Not specified in the material Canadian Centre for Cyber Security, AV26-850
UniFi Talk Not specified in the material Canadian Centre for Cyber Security, AV26-850
UniFi Protect AI Key Not specified in the material Canadian Centre for Cyber Security, AV26-850
Connect Display Cast Pro Not specified in the material Canadian Centre for Cyber Security, AV26-850
Enterprise Audio/Video Bridge Not specified in the material Canadian Centre for Cyber Security, AV26-850

Security intelligence bulletins also report that Ubiquiti released updates for at least seven additional critical vulnerabilities affecting components such as UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect and UniFi OS. The patch coverage spans network infrastructure, video surveillance, physical access and communications.

What is the technical risk?

Recent CVEs tied to Ubiquiti describe critical authentication bypass and authorization flaws in sensitive functions, with CVSS scores between 9.4 and 9.6. Based on the available information, those flaws can be exploited over the network or over an adjacent network to change device state or access files with elevated privileges.

Another critical CVE linked to Ubiquiti points to hardcoded credentials. When the FTP service is reachable, that condition could allow remote access to files with root privileges.

Independent technical reports also say Ubiquiti fixed a broad set of 22 vulnerabilities across the UniFi line, 21 of them classified as critical, and at least three rated CVSS 10.0 because of access control failures that enable privilege escalation and potential arbitrary command execution.

Researchers at VulnCheck, meanwhile, developed an exploit for CVE-2026-77539, a pre-authentication command injection vulnerability in Ubiquiti UniFi OS Server. Their work shows that public exploit code already exists for one of the flaws, raising the risk of mass exploitation if systems are not updated.

What happened with the Paraguay alert?

VECERT Analyzer issued an unconfirmed preventive alert about a supposed exfiltration and publication of a 10.5 GB database attributed to Paraguay’s Ministry of Public Health and Social Welfare. The source itself said the visible evidence is not verified, so the alleged incident remains unconfirmed by independent sources.

In that same alert, VECERT Analyzer attributed the alleged activity to an actor identified as Zumarius and recommended that Paraguayan government entities review database and WAF logs for anomalous SQL queries and exfiltration flows of between 10 and 15 GB in the prior weeks.

It also advised blocking the domain biteblob on corporate secure web gateways to prevent downloads of the file allegedly tied to the incident. According to the alert, that file could contain malware or tracking tools. The group also urged rotating service account credentials with access to critical databases and checking that administration ports such as 3306 for MySQL and 1433 for MSSQL are not exposed to the internet.

How does the Synology risk look now?

The latest reference on Synology softens the immediate-risk reading tied to a specific identifier. CVE-2026-87730 is listed as rejected in a reference database that cites security@synology.com and NVD, with no CVSS or EPSS score and no inclusion in CISA’s KEV catalog.

That does not contradict CERT-PY’s advisories on Synology, but it does show that not every identifier linked to the brand’s ecosystem carries the same level of validation or urgency. In this case, the reference database itself marks the CVE as rejected.

Recent campaigns also appear in reporting on long-running intrusions, where WordPress, Zyxel and Ubiquiti flaws are combined to steal thousands of official documents. In those operations, Ubiquiti is used as one of several attack vectors against public agencies.

Sources

View all