CVE-2026-34908Active Exploitation(ui / enterprise_fortress_gateway)

CRITICALCVSS 10.0 · CRITICALCISA KEV

Exploitation observed; activity peaked at 8 mentions and remains active

Immediate actions

  • Patch ui enterprise_fortress_gateway systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-06-26. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-284

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_fortress_gateway
  • enterprise_fortress_gateway_firmware
  • enterprise_network_video_recorder
  • enterprise_network_video_recorder_core

Threat summary

  • Active exploitation appears in 24 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 56 mentions across 24 observed days

What's happening

  • Active exploitation reported across 24 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 20 signals
  • Technical details provided in 34 signals
  • General: 14 classified signals
  • Disclosure: 9 classified signals
  • Peaked 17d ago at 8 mentions (2026-06-08); latest day: 1
  • 56 total mentions across 24 days

Affected systems

Vendors
Products
enterprise_fortress_gatewayenterprise_fortress_gateway_firmwareenterprise_network_video_recorderenterprise_network_video_recorder_coreenterprise_network_video_recorder_core_firmwareenterprise_network_video_recorder_firmwareunas_2unas_2_firmwareunas_4unas_4_firmware

1 version affected across 61 products

Deep dive

Activity timeline56 mentions / 24d
02468Mentions · 2026-05-22: 3Mentions · 2026-05-23: 1Mentions · 2026-05-25: 2Mentions · 2026-05-26: 1Mentions · 2026-05-29: 1Mentions · 2026-06-03: 1Mentions · 2026-06-08: 8Mentions · 2026-06-09: 5Mentions · 2026-06-10: 3Mentions · 2026-06-11: 1Mentions · 2026-06-19: 1Mentions · 2026-06-23: 2Mentions · 2026-06-24: 8Mentions · 2026-06-25: 3Mentions · 2026-06-26: 3Mentions · 2026-06-30: 1Mentions · 2026-07-01: 1Mentions · 2026-07-02: 1Mentions · 2026-07-06: 4Mentions · 2026-07-08: 1Mentions · 2026-07-09: 1Mentions · 2026-07-13: 1Mentions · 2026-07-14: 2Mentions · 2026-08-10: 1PoC Mentioned / Linked · 2026-05-25: 1PoC Mentioned / Linked · 2026-06-08: 1PoC Mentioned / Linked · 2026-06-10: 1PoC Mentioned / Linked · 2026-06-11: 1PoC Mentioned / Linked · 2026-07-09: 1PoC Mentioned / Linked · 2026-08-10: 1Exploit Tool / Code · 2026-07-09: 1Active Exploitation · 2026-06-09: 3Active Exploitation · 2026-06-11: 1Active Exploitation · 2026-06-23: 1Active Exploitation · 2026-06-24: 7Active Exploitation · 2026-06-25: 2Active Exploitation · 2026-06-26: 2Active Exploitation · 2026-06-30: 1Active Exploitation · 2026-07-06: 4Active Exploitation · 2026-07-09: 1Active Exploitation · 2026-07-13: 1Active Exploitation · 2026-07-14: 1Patch / Workaround · 2026-05-22: 2Patch / Workaround · 2026-06-08: 3Patch / Workaround · 2026-06-09: 1Patch / Workaround · 2026-06-11: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-24: 4Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-06-26: 2Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-07-13: 1Patch / Workaround · 2026-07-14: 1Technical Details · 2026-05-22: 2Technical Details · 2026-05-23: 1Technical Details · 2026-05-25: 1Technical Details · 2026-05-26: 1Technical Details · 2026-05-29: 1Technical Details · 2026-06-08: 5Technical Details · 2026-06-09: 4Technical Details · 2026-06-10: 1Technical Details · 2026-06-11: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-24: 5Technical Details · 2026-06-25: 1Technical Details · 2026-06-26: 2Technical Details · 2026-07-02: 1Technical Details · 2026-07-06: 4Technical Details · 2026-07-09: 1Technical Details · 2026-07-13: 1Technical Details · 2026-08-10: 105-2205-2505-2906-0806-1006-1906-2406-2607-0107-0607-0907-1408-10
Signal classification5 categories
Active Exploitation
2442.9%
General
1425.0%
Disclosure
916.1%
Patch
814.3%
PoC
11.8%
Referenced assets46 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-223
Disclosure1Patch2
2026-05-231
Disclosure1
2026-05-252
Disclosure1General1
2026-05-261
Disclosure1
2026-05-291
Patch1
2026-06-031
General1
2026-06-088
Disclosure1General4Patch2PoC1
2026-06-095
Active Exploitation3General1Patch1
2026-06-103
Disclosure1General2
2026-06-111
Active Exploitation1
2026-06-191
General1
2026-06-232
Active Exploitation1Patch1
2026-06-248
Active Exploitation7Disclosure1
2026-06-253
Active Exploitation2General1
2026-06-263
Active Exploitation2Disclosure1
2026-06-301
Active Exploitation1
2026-07-011
General1
2026-07-021
Patch1
2026-07-064
Active Exploitation4
2026-07-081
General1
2026-07-091
Active Exploitation1
2026-07-131
Active Exploitation1
2026-07-142
Active Exploitation1General1
2026-08-101
Disclosure1
Full discourse20 posts
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-34908, CVE-2026-34909 & CVE-2026-34910: Vulnerabilities in Ubiquiti UniFi OS, 10.0 rating 🔥🔥🔥 Three new vulnerabilities in Ubiquiti UniFi OS allow an network attacker to make unauthorized changes, access files and execute arbitrary command. It may cause to full device compromise. 👉 https://nt.ls/oMQHo

    Post summary

    Three newly disclosed vulnerabilities (CVE‑2026‑34908, ‑34909, ‑34910) in Ubiquiti UniFi OS have a 10.0 CVSS score and allow a network attacker to modify settings, read files, and execute arbitrary commands, potentially leading to full device compromise.

    113047172.6K
    7.6K followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    🚨The UniFi OS Server RCE chain (CVE-2026-34908/34909/34910) is now being actively exploited Bishop Fox researchers discovered it is possible to chain three vulnerabilities together to achieve unauthenticated remote code execution as root - this is now already being used to deploy commodity malware See the live exploit intel 👉 https://console.defusedcyber.com/signup

    Post summary

    Bishop Fox reports that the UniFi OS Server RCE chain (CVE‑2026‑34908/34909/34910) is being exploited in the wild, chaining three vulnerabilities for unauthenticated root‑level RCE and deploying commodity malware.

    113142159.0K
    7.5K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-34908 - critical 🚨 UniFi OS - Authentication Bypass via Path Traversal (..%2f) > UniFi OS devices contain an improper access control vulnerability caused by insuffici... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-34908 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces a critical authentication bypass via path traversal vulnerability (CVE-2026-34908) in UniFi OS devices, providing technical details and a link likely containing PoC code, but does not report active exploitation, patches, or false‑positive claims.

    09031101.6K
    1.3K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(6/23追加) 🛡CVE-2025-67038 ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / CISA-ADP ・種別:コード・インジェクション (CWE-94) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Lantronix EDS5000 2.1.0.0R3 の HTTP RPC モジュールに存在する脆弱性です。 認証失敗時のログ書き込み処理で username パラメータがサニタイズされずにシェルコマンドへ連結されます。 悪用により、攻撃者が任意の OS コマンドを root 権限で実行できる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ✅攻撃前提条件 ・Lantronix EDS5000 2.1.0.0R3 を使用している ・HTTP RPC インターフェースへ攻撃者がネットワーク経由でアクセスできる ・認証失敗時のログ書き込み処理が影響を受ける状態である ・修正済みファームウェアまたは緩和策が適用されていない ✅悪用時影響 ・username パラメータ経由で任意の OS コマンドを挿入される可能性がある ・挿入されたコマンドを root 権限で実行される可能性がある ・機器の機密性、完全性、可用性に高い影響が生じる ・ネットワーク機器を踏み台化される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2025-67038 ・http://lantronix.com ・https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02 ・https://github.com/cisagov/vulnrichment/blob/develop/2025/67xxx/CVE-2025-67038.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-67038 🛡CVE-2026-34908 Ubiquiti UniFi OS Improper Access Control Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / HackerOne (CNA) ・種別:不適切なアクセス制御 (CWE-284) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H UniFi OS デバイスに存在する不適切なアクセス制御の脆弱性です。 ネットワークアクセス可能な攻撃者が、本来許可されないシステム変更を実行できる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ✅攻撃前提条件 ・影響を受ける UniFi OS デバイスまたは UniFi OS Server を使用している ・攻撃者が対象機器へネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・修正済みバージョンへ更新されていない ✅悪用時影響 ・不正なシステム変更を実行される可能性がある ・認証を回避して内部機能へ到達される可能性がある ・他の UniFi OS 脆弱性と組み合わせてリモートコード実行につながる可能性がある ・機器の機密性、完全性、可用性に高い影響が生じる ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(PwnDefend / Xservus Limited) PwnDefend は Defused honeypot とトリアージにより、UniFi OS の SAB-064 関連脆弱性を悪用した Mirai 系ボット化の実悪用を確認したと公表。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-34908 ・https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b ・https://github.com/cisagov/vulnrichment/blob/develop/2026/34xxx/CVE-2026-34908.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34908 ・https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/ 🛡CVE-2026-34909 Ubiquiti UniFi OS Path Traversal Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / HackerOne (CNA) ・種別:パス・トラバーサル (CWE-22) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H UniFi OS デバイスに存在するパス・トラバーサルの脆弱性です。 ネットワークアクセス可能な攻撃者が、基盤システム上のファイルへアクセスし、基盤アカウントへのアクセスに悪用できる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ✅攻撃前提条件 ・影響を受ける UniFi OS デバイスまたは UniFi OS Server を使用している ・攻撃者が対象機器へネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・修正済みバージョンへ更新されていない ✅悪用時影響 ・基盤システム上のファイルへアクセスされる可能性がある ・ファイルアクセスを悪用して基盤アカウントへのアクセスにつなげられる可能性がある ・他の UniFi OS 脆弱性と組み合わせて機器を侵害される可能性がある ・機密性、完全性、可用性に高い影響が生じる ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(PwnDefend / Xservus Limited) PwnDefend は Defused honeypot とトリアージにより、UniFi OS の SAB-064 関連脆弱性を悪用した Mirai 系ボット化の実悪用を確認したと公表。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-34909 ・https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b ・https://github.com/cisagov/vulnrichment/blob/develop/2026/34xxx/CVE-2026-34909.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34909 ・https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/ 🛡CVE-2026-34910 Ubiquiti UniFi OS Improper Input Validation Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / HackerOne (CNA) ・種別:不適切な入力確認 (CWE-20) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H UniFi OS デバイスに存在する不適切な入力確認の脆弱性です。 ネットワークアクセス可能な攻撃者が細工した入力を送信することで、コマンドインジェクションを実行できる可能性があります。 悪用により、対象機器上で任意の OS コマンド実行につながる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・SSVC 悪用の状況:悪用確認済 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 (GitHub) ✅攻撃前提条件 ・影響を受ける UniFi OS デバイスまたは UniFi OS Server を使用している ・攻撃者が対象機器へネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・入力検証不備を含む更新処理または関連機能が影響を受ける状態である ・修正済みバージョンへ更新されていない ✅悪用時影響 ・コマンドインジェクションを実行される可能性がある ・対象機器上で任意の OS コマンドを実行される可能性がある ・Mirai 系ボットのローダーやインプラントを配置される可能性がある ・機器の完全な侵害につながる可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(PwnDefend / Xservus Limited) PwnDefend は Defused honeypot とトリアージにより、UniFi OS の SAB-064 関連脆弱性を悪用した Mirai 系ボット化の実悪用を確認したと公表。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-34910 ・https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b ・https://github.com/cisagov/vulnrichment/blob/develop/2026/34xxx/CVE-2026-34910.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34910 ・https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/ https://www.cisa.gov/news-events/alerts/2026/06/23/cisa-adds-four-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The post announces several high‑severity CVEs, confirms that attacks are occurring in the wild, gives detailed technical data, but does not provide PoC or exploit code, and notes available patches.

    010626.7K
    44.1K followersView on X
  • mRr3b00t@UK_Daniel_Card
    General

    CVE-2026-34908

    Post summary

    The text merely lists the CVE identifier without any additional context or details.

    210601.5K
    124.4K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    UbiquitiがUniFi OSでCVSSスコア10の脆弱性3件を修正。CVE-2026-34908、CVE-2026-34909、CVE-2026-34910。なお、CVSSスコア9.1のCVE-2026-33000と7.7のCVE-2026-34911も修正されている。

    Post summary

    Ubiquiti has released firmware updates that patch three CVSS 10 vulnerabilities (CVE-2026-34908, 34909, 34910) on UniFi OS, along with CVE-2026-33000 (CVSS 9.1) and CVE-2026-34911 (CVSS 7.7).

    000712.4K
    7.6K followersView on X
  • mRr3b00t@UK_Daniel_Card
    PoC

    scanning tool from @bishopfox https://raw.githubusercontent.com/BishopFox/CVE-2026-34908-check/refs/heads/main/cve_2026_34908_check.py

    Post summary

    The post links to a BishopFox script that appears to be a scanning tool for CVE‑2026‑34908, indicating the existence of a proof‑of‑concept or verification tool but no exploit or patch information.

    00041687
    124.3K followersView on X
  • Threat Intelligence@threatintel
    General

    #ThreatProtection #CVE-2026-34908 - UniFi OS Auth Bypass #Vulnerability, read more about Symantec's protection: https://www.broadcom.com/support/security-center/protection-bulletin/cve-2026-34908-unifi-os-auth-bypass-vulnerability

    Post summary

    The tweet references CVE‑2026‑34908 and links to a Broadcom/Symantec protection bulletin, but offers no new technical information, exploit details, or patch guidance.

    000301.7K
    115.2K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    UniFi OS Server auth bypass chained with command injection enables single-request RCE. Mass scanning underway targeting 100k+ exposed endpoints, with blind exfiltration via DNS callbacks. Key technical details: • CVE-2026-34908: nginx parser differential allows unauthenticated access to internal /proxy/ endpoints via ..%2f encoding • CVE-2026-34910: Command injection in pkg_name parameter executes shell commands as service account • Payload uses `uname | base64`.requestrepo[.]com for blind RCE confirmation via DNS exfiltration • Affects UniFi OS Server ≤5.0.6, fixed in 5.0.8 (released 2026-05-21) • Service account has passwordless sudo - trivial escalation to root Attack methodology: • Mass scanner probes with spoofed Safari user agents, inconsistent OS versions • Two requests seconds apart: uname -r and uname -a for kernel fingerprinting • No HTTP response needed - DNS lookup to collaborator confirms execution • Base64-encoded system info exfiltrated as subdomain label DFIR artifacts: • Smoking gun: DNS queries to h4wiu0w9.requestrepo[.]com or any *.requestrepo[.]com from appliance • Web logs: /api/auth/validate-sso/..%2f..%2f..%2fproxy/users/api/v2/ucs/update/latest_package with pkg_name injection • Process execution: curl/uname/base64 children of web service process • Post-exploit: sudo invocations by service account, new persistence mechanisms Hunt query: Search DNS/proxy logs for requestrepo[.]com. Any hit from UniFi appliance = confirmed compromise. #DFIR_Radar

    Post summary

    The post reports that CVE-2026-34908/34910 are being actively exploited via mass scanning and DNS-based RCE, provides technical details and a workaround, and confirms a patch release.

    10110338
    1.6K followersView on X
  • HackerStorm@hackerstorm
    Active Exploitation

    23 vulnerabilities were added to the CISA KEV list this past month, with an aggressive focus on authentication bypasses and RCE bugs targeting core network-edge and monitoring infrastructure. Key Exploitation Vectors to Patch Immediately were: SimpleHelp RMM (CVE-2026-48558 - CVSS 10.0): Pre-auth OIDC signature bypass allowing immediate MSP administrative takeover and downstream deployment of TaskWeaver loader/Djinn Stealer. Splunk Enterprise (CVE-2026-20253 - CVSS 9.8): Pre-auth RCE via the PostgreSQL sidecar component. Public functional exploit is actively circulating in the wild. Oracle PeopleSoft (CVE-2026-35273 - CVSS 9.8): Missing authentication exploit actively weaponised by ShinyHunters for financial environment takeovers. Check Point Security Gateway (CVE-2026-50751 - CVSS 9.3): IKEv1 auth bypass zero-day actively leveraged by Qilin ransomware affiliates. Ubiquiti UniFi OS (CVE-2026-34908, -34909, -34910 - CVSS 10.0 each): Automated botnet campaign executing access control bypasses and command injection at scale. PTC Windchill / FlexPLM (CVE-2026-12569 - CVSS 9.8): Deserialization flaws allowing attackers to drop JSP web shells on exposed engineering pipelines. Operational Focus: Authentication and access control bypasses outpaced standard RCEs this cycle. Prioritize your SIEM (Splunk) and remote control frameworks (SimpleHelp) over individual endpoints, as attackers are intentionally targetting visibility and management layers first. Full sector matrix and action tracker: https://www.hackerstorm.com/articles/our-blog/vulnerabililty-intelligence/monthly-vulnerability-priority-report-june-2026

    Post summary

    The report highlights multiple high‑severity CVEs actively exploited in the wild and urges immediate patching of affected systems.

    10010280
    3.0K followersView on X
  • GoCocoaAI@GoCocoaAI
    Disclosure

    A command injection flaw in Lantronix EDS5000 serial-to-Ethernet device servers hit CISA's KEV catalog yesterday. CVE-2025-67038, CVSS 9.8. Federal civilian agencies have until June 26 to patch. That's 48 hours. The mechanics are as clean as they get. The HTTP RPC module constructs a shell command to log failed authentication attempts — and concatenates the supplied username directly into that command, unsanitized. Send a crafted username with OS command metacharacters. The shell executes them as root. The trigger is a failed login, meaning exploitation requires no valid credentials whatsoever, just network reachability to the HTTP RPC port. Pre-auth. Root. No complexity. Three for three on the criteria that make a CVE immediately weaponizable. Affected firmware is 2.1.0.0R3 across the EDS5008, EDS5016, and EDS5032. The vulnerability class is CWE-78 OS command injection. CVSS vector: AV:N/AC:L/PR:N/UI:N — as permissive as the scoring system allows. The device class matters here. EDS5000 units are serial device servers — they sit at the boundary between legacy serial-connected OT equipment (PLCs, RTUs, SCADA terminal servers) and IP-routed networks. A root shell on one of these is not just a box compromise. It's a potential pivot into the OT network behind it, with the ability to relay or interfere with serial communications to industrial equipment. Serial device servers have a well-earned reputation for sitting in network closets and on plant floors, quietly forgotten, unpatched for years. They are nothing if not consistent. CISA added CVE-2025-67038 on June 23 alongside three Ubiquiti UniFi OS CVEs — CVE-2026-34908 at CVSS 10.0, CVE-2026-34909, and CVE-2026-34910 — all carrying the same June 26 deadline. A four-CVE batch, two vendors, one date, coordinated federal urgency. The pattern suggests a wave, not isolated incidents. MITRE mapping: T1190 (Exploit Public-Facing Application) for initial access, T1059.004 (Unix Shell) for execution, T1068 for privilege escalation, and T1059.008 as the likely OT pivot path. Known ransomware use is currently unconfirmed, but the device class and pivot potential make this an attractive staging point. For federal agencies, June 26 is the clock. For everyone else, that deadline is yours too. Lantronix patch firmware is available. CISA ICS Advisory ICSA-26-069-02 has the full technical breakdown. If UniFi infrastructure is in scope, the CVSS 10.0 co-listed CVE warrants its own look.

    Post summary

    The post announces a high‑severity command injection CVE (CVE‑2025‑67038) in Lantronix EDS5000 devices, provides detailed technical information and a patch, but does not report active exploitation or a PoC.

    10010170
    34 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:00 UTC: CVE-2026-34908 disclosed. CISA: CVE-2026-34908 added to Known Exploited Vulnerabilities — Ubiquiti UniFi OS Status: ✅ Confirmed exploited in the wild Date added: 2026-06-23 Required action: Apply mitigations in accordance with vendor instructions, ensuring…

    Post summary

    CVE-2026-34908 was disclosed and is confirmed to be exploited in the wild; vendors recommend applying mitigations to address the issue.

    1000068
    318 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Full Tweet 🚨The UniFi OS Server RCE chain (CVE-2026-34908/34909/34910) is now being actively exploited 0day Intel: 🚨The UniFi OS Server RCE chain (CVE-2026-34908/34909/34910) is now being active

    Post summary

    The tweet reports that the UniFi OS Server RCE chain (CVE-2026-34908/34909/34910) is actively being exploited, without providing exploit code, patch details, or a PoC.

    1000066
    309 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2026-34908: 🚨The UniFi OS Server RCE chain (CVE-2026-34908/34909/34910) is now being actively exploited Bishop Fox researchers discovered it is possible to chain three vulnerabilities together to achieve unauthenticated remote code execution as root - this is now…

    Post summary

    Bishop Fox researchers report that the UniFi OS Server RCE chain (CVE-2026-34908/34909/34910) is actively exploited by chaining three vulnerabilities to achieve unauthenticated root-level remote code execution.

    1000071
    309 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    0day Intel: 🚨The UniFi OS Server RCE chain (CVE-2026-34908/34909/34910) is now being active

    Post summary

    The tweet reports that the UniFi OS Server RCE chain (CVE-2026-34908/34909/34910) is currently being exploited, but provides no PoC, exploit code, patch, or debunking information.

    1000060
    309 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Source: X search for RCE 2026 exploit Posted: 2026-06-09T06:50:44.000Z Likes: 11 0day Intel: 🚨The UniFi OS Server RCE chain (CVE-2026-34908/34909/34910) is now being active

    Post summary

    The tweet confirms that the UniFi OS Server RCE chain (CVE-2026-34908/34909/34910) is actively being exploited, but provides no PoC, patch, or detailed technical description beyond the RCE nature.

    1000070
    309 followersView on X
  • Stanislav Klevtsov@stansecure
    Patch

    Top #CVE to #patch this week 👀 - @Ubiquiti UniFi OS (CVE-2026-34908, 34909, 34910) critical flaws - @Cisco UCM (CVE-2026-20230) SSRF to root - Another two @Linux Privesc pedit COW(CVE-2026-46331), DirtyClone - @Linux kernel — new DirtyFrag family privesc, JFrog published exploit - @apache_httpd Server (CVE-2026-44631, CVE-2026-29167) - @splunk Enterprise (CVE-2026-20253) missing auth - @nginx Plus (CVE-2026-42055) - @squidproxy (CVE-2026-47729) Squidbleed, a 29-year-old memory leak found by Mythos. Update to v7.6

    Post summary

    The tweet highlights several critical CVEs that need patching, specifically urging an update to Squidproxy v7.6, but it does not provide PoC, exploit code, or evidence of active exploitation.

    10000187
    43 followersView on X
  • Adam@seoscottsdale
    General

    @grok Please perform a thorough re-review and verification of the cybersecurity supply chain thread above (the 9-part thread posted today) for technical accuracy, source quality, timeliness, and actionability. **Specific Focus Areas:** - **CVE / Vulnerability Accuracy**: Confirm exact CVE IDs (e.g. CVE-2026-34908, CVE-2026-34909, CVE-2026-34910), CVSS scores, in-the-wild exploitation status, affected products/versions (Ubiquiti UniFi OS, Lantronix EDS5000), patch availability, and the June 26 deadline / BOD 26-04 context. Cross-check CISA KEV and NVD directly. - **Incident Timelines & Attribution**: Verify dates and details for the LastPass/Klue OAuth token theft (Icarus group, ~June 12 incident, confirmed ~June 23), Tata Electronics / World Leaks data leak (Apple supply chain exposure), and any post-thread updates. - **npm / Package Manager Waves**: Validate Red Hat @redhat-cloud-services compromise details (Miasma worm, ~30-32 packages / 90+ versions, compromised GitHub account + valid SLSA provenance), the Phantom Gyp / binding.gyp + node-gyp variant (~57+ packages), and earlier TanStack/Mini Shai-Hulud family hits. Confirm via Red Hat, Snyk, Unit 42, Microsoft, and primary disclosures. - **Healthcare / Third-Party Vendor Stats**: Verify the Omega Systems 2026 Healthcare IT Landscape Report figures cited via HIPAA Journal (85% operational disruptions from third-party vendors, 24% direct vendor breaches, 61% expect fatal cyberattack / patient safety impact). Assess balance of the AI adoption + vendor trust interpretation. - **"Why It Matters" & Implications**: Evaluate supply chain / OAuth / provenance / CI-CD exposure claims and downstream risks (phishing, IP theft, Apple supply chain, Salesforce data). Explicitly address implications for secure multi-agent AI systems, code/model/dependency provenance, agent deployment pipelines, and practical defenses for SMBs and healthcare organizations. - **Source Quality & Traceability**: Assess all cited or implied sources (CISA, LastPass blog, BleepingComputer, HIPAA Journal/Omega report, Unit 42, Snyk, Red Hat, Group-IB, Black Kite, etc.). Flag any unsourced/overstated claims or areas needing stronger primary

    Post summary

    The tweet is a meta‑request to re‑review and confirm details for several CVEs rather than presenting new information or an exploit.

    10000265
    12.4K followersView on X
  • TheNu11Sector@Nu11Sector
    Disclosure

    3.⚡ CVE-2026-34908: UniFi OS fails to validate authorization on certain management API endpoints. Unauthenticated HTTP requests bypass session checks — giving network-adjacent attackers write access to firewall rules, VLAN configs, and routing tables.

    Post summary

    The post discloses that UniFi OS fails to validate authorization on certain management API endpoints, allowing unauthenticated attackers write access to firewall rules, VLAN configurations and routing tables.

    1000067
    490 followersView on X
  • John Barger@JohnBarger
    Active Exploitation

    Three UniFi OS vulnerabilities are now being actively exploited—but many users may already be protected thanks to UniFi’s automatic update system. In this episode of IT SPARC Cast – CVE of the Week, @loudoggeek and I discuss: CVE-2026-34908 CVE-2026-34909 CVE-2026-34910 How vulnerability chaining creates critical risk Why automatic patching matters Continuous patching vs. traditional maintenance windows What network administrators should do today Recommended Actions ✅ Update UniFi OS immediately ✅ Verify auto-updates are enabled ✅ Run the Bishop Fox detection script ✅ Audit all network infrastructure firmware ✅ Review your organization’s patch strategy If you manage UniFi networking equipment, this is an episode you don’t want to miss. 💬 feedback@itsparccast.com 🐦 @itsparccast on X 👍 Like, Subscribe, and turn on notifications for more enterprise IT and cybersecurity insights.

    Post summary

    The post announces that CVE‑2026‑34908, CVE‑2026‑34909, and CVE‑2026‑34910 in UniFi OS are currently being exploited in the wild and urges immediate patching, referencing a detection script for verification.

    0001063
    1.4K followersView on X
CPE platform detail61 entries

61 of 61 entries

PartVendorProductVersionTarget SWTarget HW
HWuienterprise_fortress_gateway---
OSuienterprise_fortress_gateway_firmware---
HWuienterprise_network_video_recorder---
HWuienterprise_network_video_recorder_core---
OSuienterprise_network_video_recorder_core_firmware---
OSuienterprise_network_video_recorder_firmware---
HWuiunas_2---
OSuiunas_2_firmware---
HWuiunas_4---
OSuiunas_4_firmware---
HWuiunas_pro---
HWuiunas_pro_4---
OSuiunas_pro_4_firmware---
HWuiunas_pro_8---
OSuiunas_pro_8_firmware---
OSuiunas_pro_firmware---
HWuiunifi_cloud_gateway_fiber---
OSuiunifi_cloud_gateway_fiber_firmware---
HWuiunifi_cloud_gateway_industrial---
OSuiunifi_cloud_gateway_industrial_firmware---
HWuiunifi_cloud_gateway_max---
OSuiunifi_cloud_gateway_max_firmware---
HWuiunifi_cloud_gateway_ultra---
OSuiunifi_cloud_gateway_ultra_firmware---
HWuiunifi_cloud_key_plus---
OSuiunifi_cloud_key_plus_firmware---
HWuiunifi_cloudkey---
HWuiunifi_cloudkey_enterprise---
OSuiunifi_cloudkey_enterprise_firmware---
OSuiunifi_cloudkey_firmware---
HWuiunifi_dream_machine---
HWuiunifi_dream_machine_beast---
OSuiunifi_dream_machine_beast_firmware---
OSuiunifi_dream_machine_firmware---
HWuiunifi_dream_machine_pro---
OSuiunifi_dream_machine_pro_firmware---
HWuiunifi_dream_machine_pro_max---
OSuiunifi_dream_machine_pro_max_firmware---
HWuiunifi_dream_machine_special_edition---
OSuiunifi_dream_machine_special_edition_firmware---
HWuiunifi_dream_router---
HWuiunifi_dream_router_5g_max---
OSuiunifi_dream_router_5g_max_firmware---
HWuiunifi_dream_router_7---
OSuiunifi_dream_router_7_firmware---
OSuiunifi_dream_router_firmware---
HWuiunifi_dream_wall---
OSuiunifi_dream_wall_firmware---
HWuiunifi_express_7---
OSuiunifi_express_7_firmware---
HWuiunifi_network_video_recorder---
OSuiunifi_network_video_recorder_firmware---
HWuiunifi_network_video_recorder_g2---
OSuiunifi_network_video_recorder_g2_firmware---
HWuiunifi_network_video_recorder_g2_pro---
OSuiunifi_network_video_recorder_g2_pro_firmware---
HWuiunifi_network_video_recorder_instant---
OSuiunifi_network_video_recorder_instant_firmware---
HWuiunifi_network_video_recorder_pro---
OSuiunifi_network_video_recorder_pro_firmware---
Appuiunifi_os_server---

Explore more