CVE-2026-77540: Ubiquiti Inc UniFi OS Server

Critical severity, CVSS 9.1. EPSS: 1.3% chance of exploitation in the next 30 days.

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.

Affected products

  • Ubiquiti Inc UniFi OS Server: before 5.1.37 (fixed in 5.1.37)

Published 2026-08-26. Last modified 2026-08-28.