If your office, retail store or building runs on Ubiquiti’s UniFi gear — Wi-Fi access points, network switches, security cameras, door access, or even the office phone system — there’s a security bulletin from early July 2026 that deserves your attention today, not next week. Ubiquiti has confirmed a maximum-severity flaw that lets an attacker on the network take full control of a UniFi device without a password. It’s the third critical UniFi advisory in under three months, and the pattern so far has been: patch released, quiet period, then active exploitation.

Ubiquiti’s Security Advisory Bulletin 066 discloses seven critical vulnerabilities across UniFi Connect, Talk, Access, Protect and UniFi OS, including one rated a perfect CVSS 10.0. Around 100,000 UniFi devices are currently reachable from the public internet. If your business runs any UniFi hardware, update every affected app to its latest version immediately and make sure the management console isn’t exposed to the internet.
What Actually Happened With UniFi?
On 2 July 2026, Ubiquiti published Security Advisory Bulletin 066, disclosing seven critical vulnerabilities across its UniFi product family. The most severe, tracked as CVE-2026-50746, sits in the UniFi Connect Application and carries a CVSS score of 10.0 — the maximum possible rating. In practice, that means an attacker who can simply reach a vulnerable device over the network can run commands on it directly, with no login credentials and no action required from anyone inside the business.
Security researchers at Censys estimate roughly 100,000 UniFi OS devices are currently sitting on the public internet, reachable by anyone scanning for them. That’s the group most immediately at risk, though devices tucked away on an internal network aren’t automatically safe either — more on that below.
Which UniFi Products Are Affected?
The advisory covers seven critical flaws spread across five different UniFi applications, all of which share the same underlying platform. Here’s the full list:
| Product | Affected Versions | CVE | CVSS | Fixed Version |
|---|---|---|---|---|
| UniFi Connect Application | 3.4.16 and earlier | CVE-2026-50746 | 10.0 | 3.4.20+ |
| UniFi Talk Application | 5.1.2 and earlier | CVE-2026-50747 | 9.9 | 5.2.2+ |
| UniFi Access Application | 4.2.28 and earlier | CVE-2026-50748 | 9.9 | 4.2.29+ |
| UniFi Access Application | 4.2.28 and earlier | CVE-2026-54400 | 9.1 | 4.2.29+ |
| UniFi OS Server | 5.1.15 and earlier | CVE-2026-54402 | 9.9 | 5.1.19+ |
| UniFi Protect Application | 7.1.77 and earlier | CVE-2026-55115 | 9.9 | 7.1.83+ |
| UniFi OS Server | 5.1.15 and earlier | CVE-2026-55116 | 9.0 | 5.1.19+ |
Affected hardware families listed by Ubiquiti include the UDM, UDM-Pro, UDM-SE, UDR, UCG, UNVR and UNAS ranges, along with the software applications that run on them — meaning most small business setups with a Dream Machine, Cloud Gateway, NVR, or NAS device sitting behind the scenes are worth checking.
Why This Is More Than an IT Problem
What sets this advisory apart is what UniFi actually controls in a lot of Melbourne businesses. It isn’t just Wi-Fi anymore:
- UniFi Access manages physical door locks, turnstiles and building entry — a compromise here can mean an intruder unlocking doors remotely.
- UniFi Protect runs security camera and video surveillance systems.
- UniFi Talk handles VoIP phone systems and internal communications.
- UniFi Connect manages smart building systems like LED lighting and EV charging infrastructure.
If several of these run on a shared UniFi OS console — common in offices, retail fit-outs and hospitality venues — a single successful attack could hand someone control over your network, your cameras, your phones and your front door, all at once. This is why treating it as “just a router update” undersells the risk.
This Isn’t UniFi’s First Critical Alert This Year
The July bulletin follows on from a separate critical vulnerability chain Ubiquiti patched on 21 May 2026 (CVE-2026-34908, CVE-2026-34909 and CVE-2026-34910), which also allowed unauthenticated remote code execution with full root access. Security researchers confirmed that chain worked against live systems, and by 23 June, the US Cybersecurity and Infrastructure Security Agency (CISA) had added all three CVEs to its Known Exploited Vulnerabilities catalog after a Mirai-style botnet was found actively exploiting unpatched devices.

That’s a roughly one-month gap between patch release and confirmed real-world attacks. Ubiquiti has stated it has no evidence the new July flaws are being actively exploited yet — but based on the last cycle, that window can close quickly.
What Melbourne Businesses Should Do Right Now
1. Update every affected UniFi application
Check UniFi Connect, Talk, Access, Protect and UniFi OS Server against the version table above and update anything running an older release. This applies whether your gear is self-managed or hosted through a third party.
2. Get management interfaces off the public internet
UniFi consoles should never be directly reachable from the internet. Sit them behind a VPN or firewall with tight inbound rules, and confirm no admin ports are open to the world. This is a good moment to have your network reviewed by someone who does structured network cabling and infrastructure work regularly, particularly if your network has grown organically over the years.
3. If you’re still on the legacy UniFi Network Application, plan the move to UniFi OS
Ubiquiti has been retiring the older UniFi Network Application platform in favour of UniFi OS, which is where current security patches land first. If your controller hasn’t been migrated yet, it’s worth scheduling that transition now rather than waiting for a forced upgrade later. Admin accounts and configuration settings carry across automatically, though devices may briefly reboot during the process, so it’s best done outside business hours.
4. Watch for signs something’s already wrong
Look for admin accounts you don’t recognise, unexpected changes to firewall rules, or unusual outbound network traffic. If your business was running an unpatched UniFi OS Server before the May patch and hasn’t been checked since, treat it as a potential compromise rather than a routine update — that means rotating passwords and stored credentials, not just installing the fix.
Frequently Asked Questions
Do I need to patch even though there’s no known exploitation yet?
Yes. The previous critical UniFi flaw took about a month to go from patch release to confirmed botnet exploitation and a spot on CISA’s Known Exploited Vulnerabilities list. A quiet week now doesn’t guarantee a quiet week next month.
What is a CVSS 10.0 score and why does it matter?
CVSS 10.0 is the highest possible severity rating a vulnerability can receive. It means the flaw can be exploited over the network, needs no password, no user interaction, and results in complete control of the device. Ratings this high are uncommon and are treated as urgent, not routine.
My UniFi controller isn’t exposed to the internet — am I safe?
You’re at meaningfully lower risk, but not immune. The flaw only requires network access, not internet access, so anyone already inside your office network — via a compromised device or a rogue connection to your Wi-Fi — could still reach an internal controller. Patching closes the gap regardless of exposure.
What if I think my UniFi system was already compromised?
Treat it as a full compromise, not a simple update. That means restoring from a known clean backup, resetting admin and Wi-Fi passwords, rotating any stored credentials, and checking for unfamiliar admin accounts or firewall changes. If you’re not confident doing this yourself, get a technician to check it properly rather than assuming the patch alone fixed it.
Not Sure If Your Network Is Exposed?
Computer Cures can check your UniFi setup, apply the latest patches, and lock down your network so it isn’t sitting exposed to the internet. We support Melbourne businesses with everything from cybersecurity solutions to full small business IT support.
Related Computer Cures Services
UniFi covers a lot more than Wi-Fi, and so do we. If this advisory touches more of your setup than you expected, these are worth a look:
- Managed IT Services — ongoing patching and monitoring so advisories like this don’t slip through
- Business Wi-Fi Setup — for a properly segmented, secured wireless network
- Security Camera Installation — for UniFi Protect and other surveillance systems
- VoIP Setup for Melbourne Businesses — if your phone system runs on UniFi Talk
- Remote & Onsite IT Support — for hands-on help auditing and patching your network
Sources: Ubiquiti Security Advisory Bulletin 066 (community.ui.com); Centre for Cybersecurity Belgium advisory, “Warning: Critical Vulnerabilities in Ubiquiti UniFi OS, Patch Immediately”; Tech Times, “UniFi CVSS 10.0 Flaw Exposes 100,000 Endpoints to Unauthenticated Takeover” (8 July 2026); HostiFi newsletter, “Upcoming UniFi OS Upgrade – What to Expect.” This article is general security guidance and not a substitute for a direct network audit of your specific UniFi deployment.





