Tendvane

← All articles

NetworkAugust 27, 2026

If your home cameras say UniFi on them, update today

Three separate flaws scored a perfect 10.0 out of 10 this week, all of them in Ubiquiti's UniFi range: the networking and camera gear that has quietly become the default for anyone who wanted something better than the box their broadband provider posted them.

Ubiquiti published the batch on 26 August. Twenty-two vulnerabilities, twenty-one of them rated critical. The three worst are CVE-2026-77537 in the UniFi Protect camera application, where careless input handling lets an attacker with no account at all run commands on the box; CVE-2026-77550 in UniFi OS Server, which allows the login to be bypassed outright; and CVE-2026-77554 in UniFi Talk, the VoIP phone system, another command injection. All three are described as low complexity and requiring nothing whatsoever from you: no click, no password, no mistake on your part. The fixed versions are UniFi Protect 7.2.105, UniFi OS Server 5.1.21 and UniFi Talk 5.3.2, or anything newer.

Nobody has reported these being used in attacks yet, and that gap is the window you want to update in. Censys counts more than 100,000 UniFi OS installations reachable directly from the internet, and Ubiquiti hardware has a long history of being conscripted into botnets that criminals use to hide where their traffic comes from. A camera system a stranger can run commands on is also, obviously, a camera system a stranger can watch.

If you own this gear, open your UniFi console and take the updates now rather than at the weekend, and turn automatic application updates on while you're in there. If you don't, the wider point holds anyway: cameras, doorbells, printers and NAS boxes all run software nobody in the house ever thinks about, and they sit on the same network as your PC. Tendvane's Network scan lists what's actually connected to yours, which is usually more than people expect.

Sources

Download Tendvane