CVE-2026-34910Active Exploitation(ui / enterprise_fortress_gateway)

CRITICALCVSS 10.0 · CRITICALCISA KEV

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch ui enterprise_fortress_gateway systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-06-26. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-20

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_fortress_gateway
  • enterprise_fortress_gateway_firmware
  • enterprise_network_video_recorder
  • enterprise_network_video_recorder_core

Threat summary

  • Active exploitation appears in 15 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 53 mentions across 24 observed days

What's happening

  • Active exploitation reported across 15 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 16 signals
  • Technical details provided in 28 signals
  • Disclosure: 14 classified signals
  • General: 12 classified signals
  • Peaked 16d ago at 6 mentions (2026-06-08); latest day: 1
  • 53 total mentions across 24 days

Affected systems

Vendors
Products
enterprise_fortress_gatewayenterprise_fortress_gateway_firmwareenterprise_network_video_recorderenterprise_network_video_recorder_coreenterprise_network_video_recorder_core_firmwareenterprise_network_video_recorder_firmwareunas_2unas_2_firmwareunas_4unas_4_firmware

1 version affected across 61 products

Deep dive

Activity timeline53 mentions / 24d
02356Mentions · 2026-05-22: 4Mentions · 2026-05-23: 2Mentions · 2026-05-25: 1Mentions · 2026-05-26: 2Mentions · 2026-05-27: 1Mentions · 2026-05-29: 1Mentions · 2026-06-03: 1Mentions · 2026-06-08: 6Mentions · 2026-06-09: 3Mentions · 2026-06-10: 5Mentions · 2026-06-11: 1Mentions · 2026-06-23: 2Mentions · 2026-06-24: 5Mentions · 2026-06-25: 2Mentions · 2026-06-26: 4Mentions · 2026-06-28: 1Mentions · 2026-06-29: 1Mentions · 2026-07-01: 2Mentions · 2026-07-08: 1Mentions · 2026-07-14: 4Mentions · 2026-08-11: 1Mentions · 2026-08-25: 1Mentions · 2026-08-27: 1Mentions · 2026-09-30: 1PoC Mentioned / Linked · 2026-06-08: 1PoC Mentioned / Linked · 2026-06-09: 1PoC Mentioned / Linked · 2026-06-11: 1PoC Mentioned / Linked · 2026-06-24: 1PoC Mentioned / Linked · 2026-08-11: 1PoC Mentioned / Linked · 2026-08-27: 1Exploit Tool / Code · 2026-06-09: 1Exploit Tool / Code · 2026-06-11: 1Exploit Tool / Code · 2026-08-11: 1Exploit Tool / Code · 2026-08-27: 1Active Exploitation · 2026-05-23: 1Active Exploitation · 2026-06-10: 2Active Exploitation · 2026-06-11: 1Active Exploitation · 2026-06-23: 1Active Exploitation · 2026-06-24: 4Active Exploitation · 2026-06-25: 1Active Exploitation · 2026-06-26: 2Active Exploitation · 2026-07-14: 3Patch / Workaround · 2026-05-22: 2Patch / Workaround · 2026-05-29: 1Patch / Workaround · 2026-06-08: 2Patch / Workaround · 2026-06-09: 1Patch / Workaround · 2026-06-11: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-24: 3Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-06-26: 2Patch / Workaround · 2026-07-14: 2Technical Details · 2026-05-22: 3Technical Details · 2026-05-23: 1Technical Details · 2026-05-25: 1Technical Details · 2026-05-26: 1Technical Details · 2026-05-29: 1Technical Details · 2026-06-08: 3Technical Details · 2026-06-09: 2Technical Details · 2026-06-10: 3Technical Details · 2026-06-11: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-24: 4Technical Details · 2026-06-25: 1Technical Details · 2026-06-26: 2Technical Details · 2026-06-28: 1Technical Details · 2026-06-29: 1Technical Details · 2026-07-01: 1Technical Details · 2026-08-11: 105-2205-2505-2706-0306-0906-1106-2406-2606-2907-0808-1108-2709-30
Signal classification5 categories
Active Exploitation
1528.8%
Disclosure
1426.9%
General
1223.1%
Patch
713.5%
PoC
47.7%
Referenced assets43 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-224
Disclosure2Patch2
2026-05-232
Active Exploitation1Disclosure1
2026-05-251
Disclosure1
2026-05-262
Disclosure1General1
2026-05-271
General1
2026-05-291
Patch1
2026-06-031
Disclosure1
2026-06-086
General3Patch2PoC1
2026-06-093
Disclosure1Patch1PoC1
2026-06-105
Active Exploitation2General3
2026-06-111
Active Exploitation1
2026-06-232
Active Exploitation1Patch1
2026-06-245
Active Exploitation4Disclosure1
2026-06-252
Active Exploitation1General1
2026-06-264
Active Exploitation2Disclosure2
2026-06-281
Disclosure1
2026-06-291
Disclosure1
2026-07-012
Disclosure1General1
2026-07-081
Disclosure1
2026-07-144
Active Exploitation3General1
2026-08-111
PoC1
2026-08-251
General1
2026-08-271
PoC1
Full discourse20 posts
  • !Manan@0xManan

    UniFi’s auth gate reads the raw URI. Nginx routes the decoded one. That gap is unauth RCE - and Mirai already found it. CVE-2026-34910 (CVSS 10.0, CISA KEV) + CVE-2026-34909: `/api/auth/validate-sso/..%2f..%2f..%2fproxy/.../latest_package` slips past the SSO allowlist → `pkg_name` lands in `sudo systemctl stop <pkg_name>` via `/bin/sh -c`. Same primitive → arbitrary file read. Chain: encoded `..%2f` auth desync → package-update handler → semicolon inject in `pkg_name` → shell as `ucs-update`. ITW: azsxd Mirai implant. PoC: https://github.com/Boreas37/CVE-2026-34910-PoC ITW writeup: https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/ Pre-SAB-064 / pre-5.0.8 UniFi OS Server on the internet = assume probed. Bookmark this before the next console update drops. #UniFi #CVE #KEV #InfoSec #RCE

    27040322.3K
    2.2K followersView on X
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-34908, CVE-2026-34909 & CVE-2026-34910: Vulnerabilities in Ubiquiti UniFi OS, 10.0 rating 🔥🔥🔥 Three new vulnerabilities in Ubiquiti UniFi OS allow an network attacker to make unauthorized changes, access files and execute arbitrary command. It may cause to full device compromise. 👉 https://nt.ls/oMQHo

    Post summary

    Three new CVEs (CVE‑2026‑34908, 34909, 34910) in Ubiquiti UniFi OS enable attackers to modify device settings, read files, and run arbitrary commands, potentially leading to full device compromise.

    113047172.6K
    7.6K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-34910 Vendor: Ubiquiti Inc Product: UniFi OS Server Description: A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. Link: https://github.com/boreas37/cve-2026-34910-poc #dbugs_vuln

    Post summary

    A Proof‑of‑Concept exploit for CVE‑2026‑34910 has been released, with a GitHub repository providing the code; no evidence of active exploitation or patch information is presented.

    0301881.8K
    3.6K followersView on X
  • mRr3b00t@UK_Daniel_Card
    General

    Nice work on the UniFi vuln (CVE-2026-34910) by @yeahbutnahbut https://www.cve.org/CVERecord?id=CVE-2026-34910

    Post summary

    The post simply praises a UniFi vulnerability and links to the CVE record, providing no additional technical, exploit, or patch information.

    0001142.0K
    124.4K followersView on X
  • John Carroll@yeahbutnahbut
    General

    https://thecontractor.io/cve-2026-34910/

    Post summary

    The provided text only offers a URL to a CVE reference, lacking any additional context or details.

    110631.5K
    122 followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(6/23追加) 🛡CVE-2025-67038 ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / CISA-ADP ・種別:コード・インジェクション (CWE-94) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Lantronix EDS5000 2.1.0.0R3 の HTTP RPC モジュールに存在する脆弱性です。 認証失敗時のログ書き込み処理で username パラメータがサニタイズされずにシェルコマンドへ連結されます。 悪用により、攻撃者が任意の OS コマンドを root 権限で実行できる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ✅攻撃前提条件 ・Lantronix EDS5000 2.1.0.0R3 を使用している ・HTTP RPC インターフェースへ攻撃者がネットワーク経由でアクセスできる ・認証失敗時のログ書き込み処理が影響を受ける状態である ・修正済みファームウェアまたは緩和策が適用されていない ✅悪用時影響 ・username パラメータ経由で任意の OS コマンドを挿入される可能性がある ・挿入されたコマンドを root 権限で実行される可能性がある ・機器の機密性、完全性、可用性に高い影響が生じる ・ネットワーク機器を踏み台化される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2025-67038 ・http://lantronix.com ・https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02 ・https://github.com/cisagov/vulnrichment/blob/develop/2025/67xxx/CVE-2025-67038.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-67038 🛡CVE-2026-34908 Ubiquiti UniFi OS Improper Access Control Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / HackerOne (CNA) ・種別:不適切なアクセス制御 (CWE-284) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H UniFi OS デバイスに存在する不適切なアクセス制御の脆弱性です。 ネットワークアクセス可能な攻撃者が、本来許可されないシステム変更を実行できる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ✅攻撃前提条件 ・影響を受ける UniFi OS デバイスまたは UniFi OS Server を使用している ・攻撃者が対象機器へネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・修正済みバージョンへ更新されていない ✅悪用時影響 ・不正なシステム変更を実行される可能性がある ・認証を回避して内部機能へ到達される可能性がある ・他の UniFi OS 脆弱性と組み合わせてリモートコード実行につながる可能性がある ・機器の機密性、完全性、可用性に高い影響が生じる ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(PwnDefend / Xservus Limited) PwnDefend は Defused honeypot とトリアージにより、UniFi OS の SAB-064 関連脆弱性を悪用した Mirai 系ボット化の実悪用を確認したと公表。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-34908 ・https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b ・https://github.com/cisagov/vulnrichment/blob/develop/2026/34xxx/CVE-2026-34908.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34908 ・https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/ 🛡CVE-2026-34909 Ubiquiti UniFi OS Path Traversal Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / HackerOne (CNA) ・種別:パス・トラバーサル (CWE-22) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H UniFi OS デバイスに存在するパス・トラバーサルの脆弱性です。 ネットワークアクセス可能な攻撃者が、基盤システム上のファイルへアクセスし、基盤アカウントへのアクセスに悪用できる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ✅攻撃前提条件 ・影響を受ける UniFi OS デバイスまたは UniFi OS Server を使用している ・攻撃者が対象機器へネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・修正済みバージョンへ更新されていない ✅悪用時影響 ・基盤システム上のファイルへアクセスされる可能性がある ・ファイルアクセスを悪用して基盤アカウントへのアクセスにつなげられる可能性がある ・他の UniFi OS 脆弱性と組み合わせて機器を侵害される可能性がある ・機密性、完全性、可用性に高い影響が生じる ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(PwnDefend / Xservus Limited) PwnDefend は Defused honeypot とトリアージにより、UniFi OS の SAB-064 関連脆弱性を悪用した Mirai 系ボット化の実悪用を確認したと公表。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-34909 ・https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b ・https://github.com/cisagov/vulnrichment/blob/develop/2026/34xxx/CVE-2026-34909.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34909 ・https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/ 🛡CVE-2026-34910 Ubiquiti UniFi OS Improper Input Validation Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / HackerOne (CNA) ・種別:不適切な入力確認 (CWE-20) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H UniFi OS デバイスに存在する不適切な入力確認の脆弱性です。 ネットワークアクセス可能な攻撃者が細工した入力を送信することで、コマンドインジェクションを実行できる可能性があります。 悪用により、対象機器上で任意の OS コマンド実行につながる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・SSVC 悪用の状況:悪用確認済 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 (GitHub) ✅攻撃前提条件 ・影響を受ける UniFi OS デバイスまたは UniFi OS Server を使用している ・攻撃者が対象機器へネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・入力検証不備を含む更新処理または関連機能が影響を受ける状態である ・修正済みバージョンへ更新されていない ✅悪用時影響 ・コマンドインジェクションを実行される可能性がある ・対象機器上で任意の OS コマンドを実行される可能性がある ・Mirai 系ボットのローダーやインプラントを配置される可能性がある ・機器の完全な侵害につながる可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(PwnDefend / Xservus Limited) PwnDefend は Defused honeypot とトリアージにより、UniFi OS の SAB-064 関連脆弱性を悪用した Mirai 系ボット化の実悪用を確認したと公表。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-34910 ・https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b ・https://github.com/cisagov/vulnrichment/blob/develop/2026/34xxx/CVE-2026-34910.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34910 ・https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/ https://www.cisa.gov/news-events/alerts/2026/06/23/cisa-adds-four-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA が追加した CVE-2025-67038 と複数の Ubiquiti UniFi OS CVE(34908、34909、34910)は、実際に活用が検証され、詳細な技術情報とベンダーのパッチ・アドバイザリが提供されていることが示されている。

    010626.7K
    44.1K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    UbiquitiがUniFi OSでCVSSスコア10の脆弱性3件を修正。CVE-2026-34908、CVE-2026-34909、CVE-2026-34910。なお、CVSSスコア9.1のCVE-2026-33000と7.7のCVE-2026-34911も修正されている。

    Post summary

    Ubiquiti has released patches for five critical CVEs on UniFi OS, including three with CVSS 10 and two with scores 9.1 and 7.7.

    000712.4K
    7.6K followersView on X
  • mRr3b00t@UK_Daniel_Card
    General

    That's for CVE-2026-34910 now the actual packet they are sending is using one part of one CVE and then one part of CVE-2026-34910 (command exec) there's another way to exploit this with a just CVE-2026-34910. (more than one way to skin a cat)

    Post summary

    The post indicates that CVE-2026-34910 allows command execution and may be exploited via a specific packet, but provides no PoC, exploit code, or patch details.

    100511.3K
    124.4K followersView on X
  • Daniel Cuthbert@dcuthbert
    General

    The dinosaur that could... https://thecontractor.io/cve-2026-34910/

    Post summary

    The snippet contains only a headline and a link, offering no concrete information about the CVE beyond its existence.

    00050729
    33.3K followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: #CVE-2025-55182 CVE-2026-2796 CVE-2026-2768 CVE-2026-34910 CVE-2026-34909 CVE-2026-58231 CVE-2026-48907 ..🧵👇

    Post summary

    The tweet lists several CVE identifiers but offers no additional information about exploitation, patches, or technical specifics.

    11020167
    365 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    PoC

    🚨 CVE-2026-34910 - critical 🚨 UniFi OS Server - Command Injection &gt; A malicious actor with access to the network could exploit an Improper Input Validati... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-34910 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE-2026-34910 as a critical command injection flaw in UniFi OS Server and provides a Nuclei PoC template, but offers no evidence of active exploitation or patch status.

    00022182
    954 followersView on X
  • John Carroll@yeahbutnahbut
    PoC

    @BleepinComputer I wasn’t allowed to share the code for CVE-2026-34910 but it had a sushi menu of ‘what do you want to do’ very similar to @bishopfox’s teardown, original poc was root in one get, add an admin or run code - the best way to ensure no back and fourth with triage

    Post summary

    The user comments on a PoC for CVE-2026-34910, noting similarities to a bishopfox teardown, but does not share the code or elaborate on vulnerability details.

    100301.5K
    122 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    UniFi OS Server auth bypass chained with command injection enables single-request RCE. Mass scanning underway targeting 100k+ exposed endpoints, with blind exfiltration via DNS callbacks. Key technical details: • CVE-2026-34908: nginx parser differential allows unauthenticated access to internal /proxy/ endpoints via ..%2f encoding • CVE-2026-34910: Command injection in pkg_name parameter executes shell commands as service account • Payload uses `uname | base64`.requestrepo[.]com for blind RCE confirmation via DNS exfiltration • Affects UniFi OS Server ≤5.0.6, fixed in 5.0.8 (released 2026-05-21) • Service account has passwordless sudo - trivial escalation to root Attack methodology: • Mass scanner probes with spoofed Safari user agents, inconsistent OS versions • Two requests seconds apart: uname -r and uname -a for kernel fingerprinting • No HTTP response needed - DNS lookup to collaborator confirms execution • Base64-encoded system info exfiltrated as subdomain label DFIR artifacts: • Smoking gun: DNS queries to h4wiu0w9.requestrepo[.]com or any *.requestrepo[.]com from appliance • Web logs: /api/auth/validate-sso/..%2f..%2f..%2fproxy/users/api/v2/ucs/update/latest_package with pkg_name injection • Process execution: curl/uname/base64 children of web service process • Post-exploit: sudo invocations by service account, new persistence mechanisms Hunt query: Search DNS/proxy logs for requestrepo[.]com. Any hit from UniFi appliance = confirmed compromise. #DFIR_Radar

    Post summary

    The post reports ongoing mass scanning and exploitation of CVE-2026-34908/34910 on UniFi OS servers, providing a working RCE chain with DNS exfil, while also noting the available patch in version 5.0.8.

    10110338
    1.6K followersView on X
  • unit 3113 💽🔞@unitNo3113
    Active Exploitation

    omg, i'm part of the news https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/

    Post summary

    The tweet references a news article claiming that CVE-2026-34910 is being exploited in the wild to build a Mirai‑style botnet.

    00030130
    1.9K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34910 A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. https://www.cve.org/CVERecord?id=CVE-2026-34910

    Post summary

    The post announces CVE‑2026‑34910, describing an improper input validation flaw that could enable command injection on UniFi OS devices, but provides no PoC, exploit, or patch details.

    00021233
    57.8K followersView on X
  • John Carroll@yeahbutnahbut
    PoC

    So I have a CVE-2026-34910 a critical 10 against them (something that @bishopfox where allowed to talk about https://bishopfox.com/blog/popping-root-on-unifi-os-server-unauthenticated-rce-chain-detection-analysis, that I wasn't ... if I wanted the H1 payout) and what I did to get that 10 score was enable ssh into my Ubiquity device give Claude and raptor (https://github.com/gadievron/raptor) access to it, get Frida installed, and I opted for r2 for the heavy breakdown it took about 20-40 minutes end to end for a weaponized poc to add backdoors, inject users, do whatever as root

    Post summary

    The author describes constructing a weaponized proof of concept for CVE‑2026‑34910 on a Ubiquity device, employing tools such as raptor and Frida to gain root, but provides no evidence of wild exploitation, patches, or detailed technical analysis.

    10010229
    126 followersView on X
  • GoCocoaAI@GoCocoaAI
    Disclosure

    A command injection flaw in Lantronix EDS5000 serial-to-Ethernet device servers hit CISA's KEV catalog yesterday. CVE-2025-67038, CVSS 9.8. Federal civilian agencies have until June 26 to patch. That's 48 hours. The mechanics are as clean as they get. The HTTP RPC module constructs a shell command to log failed authentication attempts — and concatenates the supplied username directly into that command, unsanitized. Send a crafted username with OS command metacharacters. The shell executes them as root. The trigger is a failed login, meaning exploitation requires no valid credentials whatsoever, just network reachability to the HTTP RPC port. Pre-auth. Root. No complexity. Three for three on the criteria that make a CVE immediately weaponizable. Affected firmware is 2.1.0.0R3 across the EDS5008, EDS5016, and EDS5032. The vulnerability class is CWE-78 OS command injection. CVSS vector: AV:N/AC:L/PR:N/UI:N — as permissive as the scoring system allows. The device class matters here. EDS5000 units are serial device servers — they sit at the boundary between legacy serial-connected OT equipment (PLCs, RTUs, SCADA terminal servers) and IP-routed networks. A root shell on one of these is not just a box compromise. It's a potential pivot into the OT network behind it, with the ability to relay or interfere with serial communications to industrial equipment. Serial device servers have a well-earned reputation for sitting in network closets and on plant floors, quietly forgotten, unpatched for years. They are nothing if not consistent. CISA added CVE-2025-67038 on June 23 alongside three Ubiquiti UniFi OS CVEs — CVE-2026-34908 at CVSS 10.0, CVE-2026-34909, and CVE-2026-34910 — all carrying the same June 26 deadline. A four-CVE batch, two vendors, one date, coordinated federal urgency. The pattern suggests a wave, not isolated incidents. MITRE mapping: T1190 (Exploit Public-Facing Application) for initial access, T1059.004 (Unix Shell) for execution, T1068 for privilege escalation, and T1059.008 as the likely OT pivot path. Known ransomware use is currently unconfirmed, but the device class and pivot potential make this an attractive staging point. For federal agencies, June 26 is the clock. For everyone else, that deadline is yours too. Lantronix patch firmware is available. CISA ICS Advisory ICSA-26-069-02 has the full technical breakdown. If UniFi infrastructure is in scope, the CVSS 10.0 co-listed CVE warrants its own look.

    Post summary

    The post announces the CVE, details its technical aspects and urgency, and provides patch information, focusing on disclosure rather than active exploitation or tool availability.

    10010170
    34 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:00 UTC: CVE-2026-34910 disclosed. CISA: CVE-2026-34910 added to Known Exploited Vulnerabilities — Ubiquiti UniFi OS Status: ✅ Confirmed exploited in the wild Date added: 2026-06-23 Required action: Apply mitigations in accordance with vendor instructions, ensuring…

    Post summary

    CVE-2026-34910 has been disclosed and is confirmed to be actively exploited in the wild; vendors have released mitigation instructions that users should apply.

    1000072
    318 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2026-34910. Status: ✅ Confirmed exploited in the wild Date added: 2026-06-23 Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance…

    Post summary

    CVE-2026-34910 is confirmed to be actively exploited in the wild, with remediation guided by vendor instructions and CISA’s BOD 26-04.

    1000043
    318 followersView on X
  • Adam@seoscottsdale
    General

    @grok Please perform a thorough re-review and verification of the cybersecurity supply chain thread above (the 9-part thread posted today) for technical accuracy, source quality, timeliness, and actionability. **Specific Focus Areas:** - **CVE / Vulnerability Accuracy**: Confirm exact CVE IDs (e.g. CVE-2026-34908, CVE-2026-34909, CVE-2026-34910), CVSS scores, in-the-wild exploitation status, affected products/versions (Ubiquiti UniFi OS, Lantronix EDS5000), patch availability, and the June 26 deadline / BOD 26-04 context. Cross-check CISA KEV and NVD directly. - **Incident Timelines & Attribution**: Verify dates and details for the LastPass/Klue OAuth token theft (Icarus group, ~June 12 incident, confirmed ~June 23), Tata Electronics / World Leaks data leak (Apple supply chain exposure), and any post-thread updates. - **npm / Package Manager Waves**: Validate Red Hat @redhat-cloud-services compromise details (Miasma worm, ~30-32 packages / 90+ versions, compromised GitHub account + valid SLSA provenance), the Phantom Gyp / binding.gyp + node-gyp variant (~57+ packages), and earlier TanStack/Mini Shai-Hulud family hits. Confirm via Red Hat, Snyk, Unit 42, Microsoft, and primary disclosures. - **Healthcare / Third-Party Vendor Stats**: Verify the Omega Systems 2026 Healthcare IT Landscape Report figures cited via HIPAA Journal (85% operational disruptions from third-party vendors, 24% direct vendor breaches, 61% expect fatal cyberattack / patient safety impact). Assess balance of the AI adoption + vendor trust interpretation. - **"Why It Matters" & Implications**: Evaluate supply chain / OAuth / provenance / CI-CD exposure claims and downstream risks (phishing, IP theft, Apple supply chain, Salesforce data). Explicitly address implications for secure multi-agent AI systems, code/model/dependency provenance, agent deployment pipelines, and practical defenses for SMBs and healthcare organizations. - **Source Quality & Traceability**: Assess all cited or implied sources (CISA, LastPass blog, BleepingComputer, HIPAA Journal/Omega report, Unit 42, Snyk, Red Hat, Group-IB, Black Kite, etc.). Flag any unsourced/overstated claims or areas needing stronger primary

    Post summary

    The message is a request to verify accuracy and completeness of multiple CVE details, incidents, and supply‑chain concerns, rather than presenting new or actionable information about a specific vulnerability.

    10000265
    12.4K followersView on X
CPE platform detail61 entries

61 of 61 entries

PartVendorProductVersionTarget SWTarget HW
HWuienterprise_fortress_gateway---
OSuienterprise_fortress_gateway_firmware---
HWuienterprise_network_video_recorder---
HWuienterprise_network_video_recorder_core---
OSuienterprise_network_video_recorder_core_firmware---
OSuienterprise_network_video_recorder_firmware---
HWuiunas_2---
OSuiunas_2_firmware---
HWuiunas_4---
OSuiunas_4_firmware---
HWuiunas_pro---
HWuiunas_pro_4---
OSuiunas_pro_4_firmware---
HWuiunas_pro_8---
OSuiunas_pro_8_firmware---
OSuiunas_pro_firmware---
HWuiunifi_cloud_gateway_fiber---
OSuiunifi_cloud_gateway_fiber_firmware---
HWuiunifi_cloud_gateway_industrial---
OSuiunifi_cloud_gateway_industrial_firmware---
HWuiunifi_cloud_gateway_max---
OSuiunifi_cloud_gateway_max_firmware---
HWuiunifi_cloud_gateway_ultra---
OSuiunifi_cloud_gateway_ultra_firmware---
HWuiunifi_cloud_key_plus---
OSuiunifi_cloud_key_plus_firmware---
HWuiunifi_cloudkey---
HWuiunifi_cloudkey_enterprise---
OSuiunifi_cloudkey_enterprise_firmware---
OSuiunifi_cloudkey_firmware---
HWuiunifi_dream_machine---
HWuiunifi_dream_machine_beast---
OSuiunifi_dream_machine_beast_firmware---
OSuiunifi_dream_machine_firmware---
HWuiunifi_dream_machine_pro---
OSuiunifi_dream_machine_pro_firmware---
HWuiunifi_dream_machine_pro_max---
OSuiunifi_dream_machine_pro_max_firmware---
HWuiunifi_dream_machine_special_edition---
OSuiunifi_dream_machine_special_edition_firmware---
HWuiunifi_dream_router---
HWuiunifi_dream_router_5g_max---
OSuiunifi_dream_router_5g_max_firmware---
HWuiunifi_dream_router_7---
OSuiunifi_dream_router_7_firmware---
OSuiunifi_dream_router_firmware---
HWuiunifi_dream_wall---
OSuiunifi_dream_wall_firmware---
HWuiunifi_express_7---
OSuiunifi_express_7_firmware---
HWuiunifi_network_video_recorder---
OSuiunifi_network_video_recorder_firmware---
HWuiunifi_network_video_recorder_g2---
OSuiunifi_network_video_recorder_g2_firmware---
HWuiunifi_network_video_recorder_g2_pro---
OSuiunifi_network_video_recorder_g2_pro_firmware---
HWuiunifi_network_video_recorder_instant---
OSuiunifi_network_video_recorder_instant_firmware---
HWuiunifi_network_video_recorder_pro---
OSuiunifi_network_video_recorder_pro_firmware---
Appuiunifi_os_server---

Explore more