DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:12:51ZSOURCES: 14CRITICAL: 31
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — Sampled credentials from the FortiBleed dataset and confirmed they are authentic. Many of… /// @MsftSecIntel CRITICAL — Tracking FortiBleed downstream activity. Buyers of the FortiGate credential sets are… /// @TalosSecurity CRITICAL — FortiBleed is just one piece of a broader IAB operation. The same Russian-speaking actor… /// @MalwareHunterTeam CRITICAL — The Gentlemen RaaS internal data leak (May 2026, ~16GB) confirmed operators actively… /// @CrowdStrike CRITICAL — Gentlemen RaaS affiliates are deploying GentleKiller variants that specifically target…
31Critical Threats
18Active CVEs
19IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-34908PUBLISHED: 2026-05-21
CRITICALCVE-2026-34908★ CISA KEV LISTED

Ubiquiti UniFi OS Auth Bypass — Unauthenticated RCE Chain (Anchor)

VENDOR: Ubiquiti//PRODUCT: UniFi OS (Cloud Gateways, Network Controllers, Protect NVRs, Access Hubs)
10
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
PUBLIC EXPLOIT

CVE-2026-34908 is the anchor of a three-CVE chain (with CVE-2026-34909 and CVE-2026-34910) that yields a fully unauthenticated reverse shell with root privileges on any UniFi OS device. BishopFox confirmed the bypass roots in NGINX processing of crafted requests that resolve auth-exempt prefixes to authenticated internal routes; the command-injection stage exploits unsanitized package names in the update handler. CISA added all three to KEV on June 23, 2026, with a federal remediation deadline of June 26, 2026 (today); Defused Cyber observed in-the-wild exploitation deploying commodity malware, and a public PoC chaining all three is available on GitHub.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONSUniFi OS < 5.0.8 (Server); < 5.1.12 (most devices); < 5.1.10 (UNAS); < 5.1.11 (UDM-Beast)
  • CISA KEV – June 23 2026: https://www.cisa.gov/news-events/alerts/2026/06/23/cisa-adds-four-known-exploited-vulnerabilities-catalog
  • Ubiquiti Security Advisory Bulletin 064: https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b
  • SecurityWeek – Critical Ubiquiti Vulnerabilities in Attackers' Crosshairs: https://www.securityweek.com/critical-ubiquiti-vulnerabilities-in-attackers-crosshairs/
  • The Hacker News – CISA Warns Critical Lantronix EDS5000 Flaw: https://thehackernews.com/2026/06/cisa-warns-critical-lantronix-eds5000.html
  • SecurityOnline – CISA Adds Four Exploited Flaws to KEV: https://securityonline.info/cisa-kev-catalog-exploited-flaws/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn