Ubiquiti Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Ubiquiti products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

4

In CISA KEV

4

Beyond CISA KEV

0

Sensor Observed

1

Virtual Patch Available

1

Ubiquiti KEVs Added by Year

Loading...

4 Ubiquiti KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2026-34910

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a...

Confirmed In CISA 09 Jun 2026
CVE-2026-34909

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the...

Confirmed In CISA 09 Jun 2026
CVE-2026-34908

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized...

Confirmed In CISA 09 Jun 2026
CVE-2010-5330

On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not...

Confirmed In CISA 15 Apr 2022

Common Vulnerability Classes (CWE)

  • CWE-20 — Improper Input Validation 1
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
  • CWE-284 — Improper Access Control 1
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology