DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:07:52ZSOURCES: 14CRITICAL: 34
⚠ ACTIVE ALERTS
@AlvieriD CRITICAL — CORRELATED | Actor '888' listing on PwnForums: claims 35GB of Accenture source code,… /// @DarkWebInformer CRITICAL — CORRELATED | Prinz Eugen ransomware operation — actor ROOTBOY (aka avtokz / GERMANIA)… /// @MalwareHunterTeam CRITICAL — CORRELATED | PolinRider (DPRK / Famous Chollima / Contagious Interview) supply chain… /// @GossiTheDog CRITICAL — CORRELATED | CVE-2026-8037 Progress Kemp LoadMaster pre-auth RCE — exploitation attempts… /// @FalconFeedsio CRITICAL — CORRELATED | Tracking '888' forum listing for Accenture data (July 6, 2026). Dataset:…
34Critical Threats
19Active CVEs
10IOCs Tracked
7New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-50746PUBLISHED: 2026-07-02
CRITICALCVE-2026-50746

Ubiquiti UniFi Connect Application Improper Access Control / Command Injection

VENDOR: Ubiquiti//PRODUCT: UniFi Connect Application
10
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
NO KNOWN EXPLOIT

An improper access control (CWE-284) flaw in UniFi Connect Application allows any network-adjacent attacker to perform OS-level command injection on the host device without authentication. The flaw is part of Ubiquiti Security Advisory Bulletin 066, which disclosed 25 vulnerabilities across UniFi Connect, Talk, Access, Protect, and OS; Censys estimates ~100,000 UniFi OS endpoints are internet-accessible. No confirmed in-the-wild exploitation at time of writing, but a structurally identical prior CVE chain (CVE-2026-34908/09/10) was added to CISA KEV in June after real-world attacks. Patch to UniFi Connect Application 3.4.20 or later.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONSUniFi Connect Application versions 3.4.16 and earlier
  • https://thehackernews.com/2026/07/ubiquiti-patches-critical-unifi-flaws.html
  • https://fieldeffect.com/blog/ubiquiti-patches-multiple-critical-vulnerabilities-in-unifi-products/
  • https://www.techtimes.com/articles/319919/20260708/unifi-cvss-100-flaw-exposes-100000-endpoints-unauthenticated-takeover.htm
  • https://cybersecuritynews.com/ubiquiti-disclosed-25-flaws/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn