The images in this article were generated with artificial intelligence. How we publish
Ubiquiti has released corrections for two important vulnerabilities in its UniFi Network management software (also known as UniFi Controller), the tool many administrators use to configure, monitor and optimize access points, switches and gateways from the UniFi family. One of the failures, listed with maximum severity, would allow an attacker to take control of user accounts without the need for interaction by the victim, which makes the update a priority for any exposed deployment.
The manufacturer describes UniFi Network as a platform that "combines powerful Internet gateways with scalable Wi-Fi and switching" and offers real-time traffic panels and visual topology maps; it also recommends as a preferred way of deployment the use of a UniFi Cloud Gateway rather than hosting it on a self-hosted server or equipment. You can see the official introduction to the Ubiquiti help center: help.ui.com - UniFi Network.

The most serious vulnerability, recorded as CVE-2026-22557, affects the versions 10.1.85 and above of the UniFi Network Application and was fixed in the versions 10.1.89 below. According to the company's own technical note, an attacker with network access could abuse a condition of path traversal to read files from the underlying system that, in turn, could be manipulated to get access to internal accounts. The alarming feature of this failure is that its exploitation is considered to be of low complexity and does not require user interaction, which makes it easier for malicious actors already on the same network to scale their impact; Ubiquiti's recommendation and patch details are available in your public notice: Ubiquiti Community - Security Advisory.
The second corrected vulnerability is a NoSQL injection that requires authentication, but is also dangerous because it allows a user with credentials or initial access to the system to raise their privileges within the application. NoSQL database injections are a known vector and their operation and mitigation are well documented by the security community; if you want to deepen technical concepts, OWASP maintains an explanatory input on NoSQL Injection, and in the case of cross-border path you can see the OWASP guide on Path Traversal.
These corrections come in a context in which Ubiquiti's network products have often appeared as attractive targets for state actors and criminal gangs. In recent years, campaigns that committed routers and other devices to build botnets or as pivot points in more complex operations have been documented, so any vulnerability in management software that facilitates accountability or the escalation of privileges deserves immediate attention by managers and security officials.

If you manage a UniFi installation, the essential and first-hand step is to update: install version 10.1.89 or higher of the UniFi Network Application as soon as possible. Beyond the patch, it is appropriate to review the deployment architecture: if your controller is directly exposed to unreliable networks, it is worth moving it to a separate management network or deploying it to a UniFi Cloud Gateway, as recommended by the manufacturer. Limiting access to the management port by firewall and VPN rules and applying multifactor authentication (MFA) in administrative accounts are measures that significantly reduce the risk of exploitation even if new vulnerabilities arise.
Nor should we forget the operational practices: the rotation of credentials, the audit and periodic review of log in search of anomalous access, the backup of the configuration and a clear inventory of installed versions help both to detect commitments and to regain control if something goes wrong. For organizations with more stringent requirements, isolate the management plan in a dedicated VLAN, create white lists of IP addresses that can access the controller and review external integrations are prudent steps.
Finally, it is appropriate to maintain a proactive position on information about threats and public warnings: to subscribe to the manufacturer's updates and security agency bulletins, and to validate patches before they are deployed in production, is the most responsible way to manage critical infrastructure. You can read the CVE record for more technical details about the main failure at: CVE-2026-22557 and review Ubiquiti's official notice here: Ubiquiti Security Communiqué. If you need practical guidance to audit or harden a Unifi deployment, the manufacturer's own documentation and specialized community resources are a good starting point.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...