The images in this article were generated with artificial intelligence. How we publish
The United States Agency for Infrastructure and Cybersecurity (CISA) has identified an active operating activity against network infrastructure devices: specifically against Ubiquiti Unifi OS systems and serial servers -to-Ethernet de Lantronix. The combination of critical vulnerabilities and the ease of remote exploitation make this incident an immediate risk to organizations of all sizes.
In the case of Ubiquiti, CISA has included in its catalogue of exploited vulnerabilities (KEV) three failures that allow from access control leaps to remote command execution if they are properly chained: CVE-2026-34908, CVE-2026-34909 and CVE-2026-34910. Independent researchers demonstrated that the chaining of these failures can lead to total system take, which converts UniFi drivers and link doors into vectors for subsequent deployments within a network.

For those who want to verify their technical exposure, there are public references of each EQO and detection tools: for example, the tab can be found in the NVD for CVE-2026-34908 and their partners, and Bishop Fox researchers have published a GitHub detection script that helps locate vulnerable instances in real infrastructure ( Bishop Fox - CVE-2026-34908 check).
Lantronix failure (CVE-2025-67038) affects the EDS5000 series and allows root-privileged command injection through the HTTP RPC module, due to the unsecure concatenation of user data in shell commands. Lantronix published a firmware correction and recommends updating to version 2.2.0.0R1; the manufacturer's page contains update and download information ( Lantronix - Firmware EDS5000). The NVD entry for this CVE also provides additional technical context: CVE-2025-67038 in NVD.
The regulatory reaction has been rapid: under the CISA BOD 26-04 directive, federal agencies must apply patches or mitigations available in very short time. Although this obligation applies to government entities, the practical recommendation for companies and managers is the same: to park now and assume that attempts at exploitation will continue. The guide and text of the directive are publicly available on the CISA site ( CISA - BOD 26-04).
If you cannot park immediately, implement priority network content: segmented management of UniFi and Lantronix devices outside public access, apply access control lists to limit IP origin, disable unnecessary remote administration and use VPNs or authenticated tunnels to manage them. Avoid direct exposure to the Internet of management consoles drastically reduces the risk of automated operation.
In addition to containment, make an urgent inventory: identify all UniFi and gateways drivers, and all EDS5000 units, check firmware versions and recent access records. Look for typical remote takeover engagement indicators: new processes or chronJobs, created administrative accounts, outgoing connections to unknown IPs, and changes in configuration files or certificates.

Do not trust the patch only: after updating, please note that the settings have not been modified by a previous attacker. Rote administrative credentials and keys that may have been exposed, and restore critical configurations from verified backups if you detect manipulation. The cycle of patching, auditing, and rotating credentials is as important as the update itself.
For security and operations teams, turn this alert into a detection and response exercise: deploy the Bishop Fox script to identify exposed instances, review EDR / IDS rules to detect abnormal command execution in controllers, and document recovery procedures. If you need technical references or indicators, NVD chips and manufacturer's notices are good starting points for building detection rules.
Finally, take a preventive position in the medium term: strengthen inventory management processes of IoT / OT devices, apply segmentation and least- privilege in management architectures, and require safety tests in firmware updates. Recent incidents recall that serious controllers and bridges - to- IP are lucrative objectives: protecting them must be an operational priority, not just a patching task..
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...