Skip to content
COOEY

EXPOSURES › CVE-2026-34910

CVE-2026-34910

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-06-23 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-34910 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildsupply-chain

Ubiquiti UniFi OS allows remote command injection via improper input validation, enabling attackers to execute arbitrary commands on the network.

This vulnerability permits remote command injection on Ubiquiti UniFi OS devices, allowing attackers to execute arbitrary commands if they can reach the network. For DIB organizations, this poses a severe risk as compromised UniFi devices could be leveraged to pivot into sensitive networks or exfiltrate data, potentially violating NIST 800-171 requirements for system integrity and access control. Organizations should immediately patch affected devices and review network segmentation to prevent lateral movement.

Shame score — A high-severity RCE vulnerability in a widely deployed networking product that is actively exploited, indicating a significant security oversight.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.