Ubiquiti SAB-066: CVSS 10.0 Command Injection in UniFi Connect Plus Six Additional Critical RCE/Privesc Bugs Across Entire UniFi Ecosystem — 100K+ Endpoints Internet-Exposed
Ubiquiti published Security Advisory Bulletin 066 disclosing seven critical vulnerabilities across UniFi Connect, Talk, Access, Protect, and OS Server. The lead flaw, CVE-2026-50746 (CVSS 10.0), allows any network-adjacent attacker to execute arbitrary OS commands on UniFi Connect Application hosts without authentication; six additional bugs rated 9.0–9.9 cover SQL injection, SSRF, and command injection across the rest of the product line. Censys tracks over 100,000 UniFi OS instances reachable from the public internet, and a structurally identical prior CVE chain from the same product family was already added to CISA's KEV catalog in June — making rapid exploitation of this new batch highly probable.
This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the critical severity rating as a guide to prioritization within their environment.
For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.