CVE-2026-33000: UI UniFi OS Server
Critical severity, CVSS 9.1. EPSS: 1.4% chance of exploitation in the next 30 days.
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
Affected products
- UI UniFi OS Server: before 5.0.8 (fixed in 5.0.8)
Published 2026-05-22. Last modified 2026-07-23.