DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:12:51ZSOURCES: 14CRITICAL: 31
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — Sampled credentials from the FortiBleed dataset and confirmed they are authentic. Many of… /// @MsftSecIntel CRITICAL — Tracking FortiBleed downstream activity. Buyers of the FortiGate credential sets are… /// @TalosSecurity CRITICAL — FortiBleed is just one piece of a broader IAB operation. The same Russian-speaking actor… /// @MalwareHunterTeam CRITICAL — The Gentlemen RaaS internal data leak (May 2026, ~16GB) confirmed operators actively… /// @CrowdStrike CRITICAL — Gentlemen RaaS affiliates are deploying GentleKiller variants that specifically target…
31Critical Threats
18Active CVEs
19IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-34910PUBLISHED: 2026-05-21
CRITICALCVE-2026-34910★ CISA KEV LISTED

Ubiquiti UniFi OS Unauthenticated RCE Chain – Command Injection

VENDOR: Ubiquiti//PRODUCT: UniFi OS (Cloud Gateways, Network Controllers, Protect NVRs, Access Hubs)
10
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
PUBLIC EXPLOIT

CVE-2026-34910 (improper input validation / command injection, CWE-20) is the payload stage of a three-CVE chain (with CVE-2026-34908 access-control bypass and CVE-2026-34909 path traversal) that enables a fully unauthenticated attacker with network access to achieve root-level remote code execution on any UniFi OS device. BishopFox confirmed the full chain against a live 5.0.6 target; the attack works by abusing an NGINX auth-bypass via encoded URI paths, then injecting shell metacharacters into an unsanitized package-update endpoint. CISA added all three CVEs to KEV on June 23, 2026 with a 3-day federal remediation deadline; active exploitation is confirmed in the wild with public PoC code available on GitHub.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONSAll UniFi OS devices prior to UniFi OS Server 5.0.8, firmware 5.1.12 (Express 4.0.14, UNAS 5.1.10, UDM-Beast 5.1.11)
  • https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b
  • https://www.cisa.gov/news-events/alerts/2026/06/23/cisa-adds-four-known-exploited-vulnerabilities-catalog
  • https://www.securityweek.com/critical-ubiquiti-vulnerabilities-in-attackers-crosshairs/
  • https://beazley.security/alerts-advisories/critical-vulnerability-in-ubiquiti-network-application-under-active-exploitation-cve-2026-34908-cve-2026--34909-cve-2026-34910
SHARE BRIEF:✕ Post on Xin Share on LinkedIn