# Ubiquiti vulnerabilities & exploitation

> As of 2026-10-05, Threadlinqs tracks 5 Ubiquiti CVEs, 0 in the CISA Known Exploited Vulnerabilities catalog, linked to 6 tracked threat campaigns and 4 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 5 Ubiquiti CVEs published between 2026-05-15 and 2026-05-15. The busiest month was 2026-05 (5 new CVEs). None of them is listed in CISA KEV yet.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 5 of 5 tracked Ubiquiti CVEs.

- [CVE-2026-34910](https://intel.threadlinqs.com/cve/CVE-2026-34910) — CRITICAL 10 · EPSS 0.1% · 2026-05-22
- [CVE-2026-33000](https://intel.threadlinqs.com/cve/CVE-2026-33000) — CRITICAL 9.1 · EPSS 0.1% · 2026-05-22
- [CVE-2026-34909](https://intel.threadlinqs.com/cve/CVE-2026-34909) — CRITICAL 10 · EPSS 0% · 2026-05-22
- [CVE-2026-34908](https://intel.threadlinqs.com/cve/CVE-2026-34908) — CRITICAL 10 · EPSS 0% · 2026-05-22
- [CVE-2026-34911](https://intel.threadlinqs.com/cve/CVE-2026-34911) — HIGH 7.7 · EPSS 0% · 2026-05-22

## Products affected

Threadlinqs normalises CPE and CNA product records across all 5 CVEs; 11 distinct Ubiquiti products are affected. The most frequently affected:

- UniFi OS Server — 5 CVEs
- EFG — 4 CVEs
- UDM — 4 CVEs
- UDM-Beast — 4 CVEs
- UDM-Pro — 4 CVEs
- UDM-Pro-Max — 4 CVEs
- UDM-SE — 4 CVEs
- UDR — 4 CVEs
- UDW — 4 CVEs
- UDR7 — 3 CVEs
- Express — 1 CVE

## Threat activity

6 tracked threat campaigns reference Ubiquiti products or exploit Ubiquiti CVEs:

- [Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government Data](https://intel.threadlinqs.com/threat/TL-2026-2619) — CRITICAL — 2026-09-22
- [CVE-2026-50746: Critical Unauthenticated Command Injection in Ubiquiti UniFi Connect Application (CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1159) — CRITICAL — 2026-07-10
- [CISA BOD 26-04: Risk-Based Vulnerability Remediation and CISO Reporting Mandate for FCEB Agencies](https://intel.threadlinqs.com/threat/TL-2026-1134) — MEDIUM — 2026-07-06
- [UniFi OS Server Pre-Auth RCE Chain (CVE-2026-34908/34909/34910): x-original-uri Auth-Gateway Bypass + package-update Command Injection](https://intel.threadlinqs.com/threat/TL-2026-0714) — CRITICAL — 2026-06-08
- [Ubiquiti UniFi OS — Three Max-Severity Pre-Auth Vulnerabilities (CVE-2026-34908 / 34909 / 34910) in Security Advisory Bulletin 064](https://intel.threadlinqs.com/threat/TL-2026-0563) — CRITICAL — 2026-05-22
- [APT28 Router DNS Hijacking for Adversary-in-the-Middle Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-0330) — HIGH — 2026-04-07

## Threat actors targeting Ubiquiti

Named threat actors attributed to campaigns that involve Ubiquiti products or CVEs, with the number of linked campaigns:

- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1 campaign
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1 campaign
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 1 campaign
- [Kapibala](https://intel.threadlinqs.com/actor/Kapibala) — 1 campaign

## How to prioritise Ubiquiti patching

This order follows the data Threadlinqs holds for Ubiquiti, not a generic severity checklist:

- No Ubiquiti CVE is in CISA KEV yet, so rank by exploit probability instead.
- Outside KEV, the highest EPSS scores are [CVE-2026-34910](https://intel.threadlinqs.com/cve/CVE-2026-34910) (0.1%), [CVE-2026-33000](https://intel.threadlinqs.com/cve/CVE-2026-33000) (0.1%), [CVE-2026-34909](https://intel.threadlinqs.com/cve/CVE-2026-34909) (0%).
- 4 CVEs score Critical and 1 High on CVSS v3 (maximum 10, average 9.4); sequence these after KEV and high-EPSS items.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/ubiquiti
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
