Exploitation timeline
Threadlinqs has recorded 5 Ubiquiti CVEs published between and . The busiest month was 2026-05 (5 new CVEs). None of them is listed in CISA KEV yet.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 5 of 5 tracked Ubiquiti CVEs.
- CVE-2026-34910critical 10EPSS 0.1%
- CVE-2026-33000critical 9.1EPSS 0.1%
- CVE-2026-34909critical 10EPSS 0%
- CVE-2026-34908critical 10EPSS 0%
- CVE-2026-34911high 7.7EPSS 0%
Products affected
Threadlinqs normalises CPE and CNA product records across all 5 CVEs; 11 distinct Ubiquiti products are affected. The most frequently affected:
- UniFi OS Server 5 CVEs
- EFG 4 CVEs
- UDM 4 CVEs
- UDM-Beast 4 CVEs
- UDM-Pro 4 CVEs
- UDM-Pro-Max 4 CVEs
- UDM-SE 4 CVEs
- UDR 4 CVEs
- UDW 4 CVEs
- UDR7 3 CVEs
- Express 1 CVE
Threat activity
6 tracked threat campaigns reference Ubiquiti products or exploit Ubiquiti CVEs:
- Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government DataCRITICAL
- CVE-2026-50746: Critical Unauthenticated Command Injection in Ubiquiti UniFi Connect Application (CVSS 10.0)CRITICAL
- CISA BOD 26-04: Risk-Based Vulnerability Remediation and CISO Reporting Mandate for FCEB AgenciesMEDIUM
- UniFi OS Server Pre-Auth RCE Chain (CVE-2026-34908/34909/34910): x-original-uri Auth-Gateway Bypass + package-update Command InjectionCRITICAL
- Ubiquiti UniFi OS — Three Max-Severity Pre-Auth Vulnerabilities (CVE-2026-34908 / 34909 / 34910) in Security Advisory Bulletin 064CRITICAL
- APT28 Router DNS Hijacking for Adversary-in-the-Middle Credential TheftHIGH
Threat actors targeting Ubiquiti
Named threat actors attributed to campaigns that involve Ubiquiti products or CVEs, with the number of linked campaigns:
How to prioritise Ubiquiti patching
This order follows the data Threadlinqs holds for Ubiquiti, not a generic severity checklist:
- No Ubiquiti CVE is in CISA KEV yet, so rank by exploit probability instead.
- Outside KEV, the highest EPSS scores are CVE-2026-34910 (0.1%), CVE-2026-33000 (0.1%), CVE-2026-34909 (0%).
- 4 CVEs score Critical and 1 High on CVSS v3 (maximum 10, average 9.4); sequence these after KEV and high-EPSS items.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.