← Blog
🛡️ Vulnerability13 July 2026

CVE-2026-34910: critical vulnerability in Ubiquiti UniFi OS actively exploited

CVE-2026-34910 (CVSS 10.0) affects Ubiquiti UniFi OS and is on CISA's KEV catalog. What to do today.

OCIRIA security team

CVE-2026-34910: critical vulnerability in Ubiquiti UniFi OS actively exploited

In short

A critical vulnerability (CVE-2026-34910, CVSS score 10.0 out of 10) has been identified in Ubiquiti UniFi OS devices, and it appears in CISA's catalog of actively exploited vulnerabilities (KEV) [2]. A malicious actor with network access could exploit an input validation flaw to execute commands on the system [1]. If your company uses UniFi equipment (routers, switches, controllers), today's recommendation is to identify all exposed UniFi OS devices, apply the updates published by the manufacturer as soon as they are available, and review what can access those devices from the network.

What it is and why it matters

CVE-2026-34910 is an "Improper Input Validation" vulnerability that leads to command injection in Ubiquiti's UniFi OS devices [1]. In business terms: if an attacker manages to gain access to the network where the affected equipment resides, they could go on to execute commands on it [1]. The official record does not detail whether that network access requires additional credentials or not, so it should not be assumed either way; the prudent approach is to treat the scenario as high risk while no further public detail is available.

NVD classifies it as critical, with the maximum possible score (CVSS 10.0) [1], and CISA has added it to its catalog of actively exploited vulnerabilities (KEV) [2], indicating that this is not a theoretical risk: exploitation is already underway. Network equipment like Ubiquiti's is often the entry point or transit point for all of an organization's traffic, so a breach here can affect network availability and facilitate access to other connected systems [1].

Who is affected

It affects organizations that have deployed Ubiquiti UniFi OS devices in their network infrastructure [1]. This may include routers, managed switches, access points, or controllers running this operating system. We do not have verified data on which specific models or versions are affected, nor on Ubiquiti's market share across different sectors, so the general recommendation is: if your company manages UniFi equipment, you should consider yourself within the potential scope until you confirm otherwise with the manufacturer.

How to know if you are vulnerable

The first step is to take inventory: identify which Ubiquiti UniFi OS devices your organization has, where they are located on the network, and what firmware/software version they are running. It's also worth reviewing what portion of that surface is exposed to the internet or accessible from uncontrolled networks, since the exploitation vector requires network access to the device [1]. Our OCIRIA radar continuously monitors organizations' exposed network surface, making it possible to detect equipment and services accessible from the outside that could fall within the exposure radius of this type of vulnerability. Reviewing your exposed surface is the most direct step to find out whether this specific case affects you.

How to protect yourself

  • Take inventory of all UniFi OS devices in your organization (model and version).
  • Check with the manufacturer (Ubiquiti) whether an update already exists that fixes CVE-2026-34910, and apply it as soon as it is available.
  • Reduce exposure of the management interface of these devices: avoid making it accessible from the internet and limit access to segmented administration networks.
  • Segment the network so that a compromised device does not grant direct access to the rest of the critical systems.
  • Monitor for unusual activity on network equipment, given that CISA confirms active exploitation of this vulnerability [2].
  • Periodically review your exposed surface to detect changes or new uncontrolled access points.

FAQ

Is it urgent to act?

Yes. The combination of CVSS 10.0 [1] and presence in CISA's KEV catalog due to active exploitation [2] indicates that this is a real risk already being exploited, not just a theoretical one.

Do I need to be connected to the internet to be vulnerable?

The official description indicates that the requirement is having network access to the device, not necessarily direct exposure to the internet [1]. Even so, reducing public exposure is a prudent measure.

What if I can't update right away?

While the patch is being applied, prioritize network isolation and restricting access to the management interfaces of the affected equipment, as recommended by our internal analysis.

Sources

  • [1] https://nvd.nist.gov/vuln/detail/CVE-2026-34910
  • [2] https://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json
OCIRIA security team Threat monitoring & response · data from our real-time radar Live radar