DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-50746PUBLISHED: 2026-07-02
■ CRITICALCVE-2026-50746

Ubiquiti UniFi Connect Application Improper Access Control / Command Injection

VENDOR: Ubiquiti//PRODUCT: UniFi Connect Application
10
CRITICAL
CVSS 3.1
✓
PATCH STATUS
PATCH AVAILABLE
◯
EXPLOIT STATUS
NO KNOWN EXPLOIT

An improper access control (CWE-284) flaw in UniFi Connect Application allows any network-adjacent attacker to perform OS-level command injection on the host device without authentication. The flaw is part of Ubiquiti Security Advisory Bulletin 066, which disclosed 25 vulnerabilities across UniFi Connect, Talk, Access, Protect, and OS; Censys estimates ~100,000 UniFi OS endpoints are internet-accessible. No confirmed in-the-wild exploitation at time of writing, but a structurally identical prior CVE chain (CVE-2026-34908/09/10) was added to CISA KEV in June after real-world attacks. Patch to UniFi Connect Application 3.4.20 or later.

↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONSUniFi Connect Application versions 3.4.16 and earlier
  • → https://thehackernews.com/2026/07/ubiquiti-patches-critical-unifi-flaws.html
  • → https://fieldeffect.com/blog/ubiquiti-patches-multiple-critical-vulnerabilities-in-unifi-products/
  • → https://www.techtimes.com/articles/319919/20260708/unifi-cvss-100-flaw-exposes-100000-endpoints-unauthenticated-takeover.htm
  • → https://cybersecuritynews.com/ubiquiti-disclosed-25-flaws/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn