CVE-2026-22562Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on the system that could be used for a remote code execution (RCE). Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
UniFi Play Audio Port  (Version 1.0.24 and earlier)
 Mitigation: Update UniFi Play PowerAmp to Version 1.0.38 or later
Update UniFi Play Audio Port  to Version 1.1.9 or later

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

RISING

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 4 observed days
  • Momentum state: rising

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 4 classified signals
  • Peaked 2d ago at 4 mentions (2026-04-14); latest day: 3
  • 11 total mentions across 4 days

Deep dive

Activity timeline11 mentions / 4d
01234Mentions · 2026-04-13: 1Mentions · 2026-04-14: 4Mentions · 2026-05-10: 3Mentions · 2026-06-08: 3Patch / Workaround · 2026-04-13: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-05-10: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-14: 3Technical Details · 2026-05-10: 2Technical Details · 2026-06-08: 104-1304-1405-1006-08
Signal classification3 categories
Disclosure
545.5%
General
436.4%
Patch
218.2%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-131
Patch1
2026-04-144
Disclosure3Patch1
2026-05-103
Disclosure2General1
2026-06-083
General3
Full discourse11 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: CVE-2026-22562, CVE-2026-22563, CVE-2026-22564 - critical vulnerabilities in #Ubiquiti UniFi Play PowerAmp could allow #remote attackers to complete device compromise. No user interaction may be required. #Patch #Patch #Patch

    Post summary

    The notice highlights three critical Ubiquiti UniFi Play PowerAmp CVEs that could allow remote compromise without user interaction, but offers no further technical or remediation information.

    01000191
    7.2K followersView on X
  • Dave@RideToFireStar
    General

    Yawn 🥱 2026 recap: UniFi OS: - CVE-2026-34908 - 10 - CVE-2026-34909 - 10 - CVE-2026-34910 - 10 - CVE-2026-33000 - 9.1 - CVE-2026-34911 - 7.7 UniFi Play Devices: - CVE-2026-22563 - 9.8 - CVE-2026-22562 - 9.8 - CVE-2026-22564 - 9.8 - CVE-2026-22566 - 7.5 - CVE-2026-22565 - 7.5 UniFi Network (Controller): - CVE-2026-22557 - 10 - CVE-2026-22558 - 7.7 - CVE-2026-22559 - 8.8 UniFi Protect: - CVE-2026-21633 - 8.8 - CVE-2026-21634 - 6.5 UniFi airMAX: - CVE-2026-21638 - 8.8 So much fail, and we're not even halfway through 2026. Lots of 10s and 9s. 🤡🩰

    Post summary

    The text simply lists multiple UniFi-related CVEs with severity scores, without providing any additional context such as PoC, exploit availability, active exploitation, or mitigation details.

    00000116
    1.2K followersView on X
  • Dave@RideToFireStar
    General

    Yawn 🥱 2026 recap: UniFi OS: - CVE-2026-34908 - 10 - CVE-2026-34909 - 10 - CVE-2026-34910 - 10 - CVE-2026-33000 - 9.1 - CVE-2026-34911 - 7.7 UniFi Play Devices: - CVE-2026-22563 - 9.8 - CVE-2026-22562 - 9.8 - CVE-2026-22564 - 9.8 - CVE-2026-22566 - 7.5 - CVE-2026-22565 - 7.5 UniFi Network (Controller): - CVE-2026-22557 - 10 - CVE-2026-22558 - 7.7 - CVE-2026-22559 - 8.8 UniFi Protect: - CVE-2026-21633 - 8.8 - CVE-2026-21634 - 6.5 UniFi airMAX: - CVE-2026-21638 - 8.8 So much fail, and we're not even halfway through 2026. Lots of 10s and 9s. 🤡🩰

    Post summary

    The post provides a concise list of UniFi CVE identifiers with their CVSS base scores for 2026, but contains no PoC, exploit code, patch details, or evidence of active exploitation.

    0000057
    1.2K followersView on X
  • Dave@RideToFireStar
    General

    Yawn 🥱 2026 recap: UniFi OS: - CVE-2026-34908 - 10 - CVE-2026-34909 - 10 - CVE-2026-34910 - 10 - CVE-2026-33000 - 9.1 - CVE-2026-34911 - 7.7 UniFi Play Devices: - CVE-2026-22563 - 9.8 - CVE-2026-22562 - 9.8 - CVE-2026-22564 - 9.8 - CVE-2026-22566 - 7.5 - CVE-2026-22565 - 7.5 UniFi Network (Controller): - CVE-2026-22557 - 10 - CVE-2026-22558 - 7.7 - CVE-2026-22559 - 8.8 UniFi Protect: - CVE-2026-21633 - 8.8 - CVE-2026-21634 - 6.5 UniFi airMAX: - CVE-2026-21638 - 8.8 So much fail, and we're not even halfway through 2026. Lots of 10s and 9s. 🤡🩰

    Post summary

    A list of UniFi product CVEs with associated severity scores, offering no technical, exploit, or mitigation details.

    00000110
    1.2K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    https://lyrie.ai/research/research/cve-2026-22562-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The linked advisory announces CVE-2026-22562, outlines the technical details of the vulnerability, and recommends a patch or mitigation.

    0000016
    189 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVSS 9.8 CRITICAL · CVE-2026-22562 · 9.8 → 1.0.35 CVE: CVE-2026-22562 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post lists CVE-2026-22562 as a critical vulnerability with a CVSS score of 9.8, but provides no additional technical, exploit, or mitigation information.

    0000030
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-22562 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write…

    Post summary

    A new critical Path Traversal flaw (CVE-2026‑22562) in UniFi Play firmware is disclosed, rated CVSS 9.8, and allows an attacker with network access to write arbitrary files.

    0000064
    197 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Five critical bugs (CVE-2026-22562-22566) in UniFi Play PowerAmp ≤1.0.35 and Audio Port ≤1.0.24 enable RCE, command injection, WiFi credential theft, fixed in 1.0.38 and 1.1.9. https://threatcluster.io/cluster/multiple-vulnerabilities-discovered-in-unifi-play-devices-34d3faaf

    Post summary

    Five critical RCE and command‑injection bugs were disclosed in UniFi Play PowerAmp and Audio Port, with patches 1.0.38 and 1.1.9 now available.

    0000070
    156 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22562 A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on the system that co… https://www.cve.org/CVERecord?id=CVE-2026-22562

    Post summary

    The post announces a Path Traversal flaw in UniFi Play firmware that could enable file writes, but offers no evidence of active exploitation, PoC, or remediation.

    00000106
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22562 Path Traversal Vulnerability in UniFi Play Devices Enabling Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22562

    Post summary

    The post announces CVE-2026-22562, a path traversal vulnerability in UniFi Play devices that can result in remote code execution, and links to detailed information on Vulmon.

    0000057
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-22562: CRITICAL] Warning: UniFi Play devices are vulnerable to Path Traversal exploit for remote code execution. Update PowerAmp to v1.0.38+ and Audio Port to v1.1.9+ to stay protected.#cve,CVE-2026-22562,#cybersecurity https://cvefind.com/CVE-2026-22562

    Post summary

    UniFi Play devices have a path‑traversal flaw that allows remote code execution; updating PowerAmp and Audio Port to the mentioned versions mitigates the issue.

    0000065
    620 followersView on X

Explore more