CVE-2026-55116: UI UniFi Connect
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.
Affected products
- UI UniFi Connect: before 3.4.20 (fixed in 3.4.20)
Published 2026-07-02. Last modified 2026-07-09.