CVE-2026-54402General(ui / enterprise_firewall_core)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ui enterprise_firewall_core systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_firewall_core
  • enterprise_firewall_core_firmware
  • enterprise_fortress_gateway
  • enterprise_fortress_gateway_firmware

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-07-03); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
enterprise_firewall_coreenterprise_firewall_core_firmwareenterprise_fortress_gatewayenterprise_fortress_gateway_firmwareenterprise_network_video_recorderenterprise_network_video_recorder_coreenterprise_network_video_recorder_core_firmwareenterprise_network_video_recorder_firmwareunas_2unas_2_firmware

1 version affected across 63 products

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-07-02: 1Mentions · 2026-07-03: 2Mentions · 2026-07-10: 1Mentions · 2026-07-20: 1Mentions · 2026-08-03: 1Patch / Workaround · 2026-07-03: 2Patch / Workaround · 2026-07-10: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-03: 2Technical Details · 2026-07-10: 107-0207-0307-1007-2008-03
Signal classification3 categories
General
350.0%
Patch
233.3%
Disclosure
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-07-021
General1
2026-07-032
Disclosure1Patch1
2026-07-101
Patch1
2026-07-201
General1
2026-08-031
General1
Full discourse6 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Ubiquiti UniFi: Command Injection in UniFi OS + Privilege Escalation in UniFi Access (CVE-2026-54402, CVE-2026-54400) Ubiquiti's SA Bulletin 066 covers two critical flaws. CVE-2026-54402 is an improper input validation issue in UniFi OS that leads to command injection on the host: a network-adjacent attacker with low privileges can inject and execute arbitrary OS commands on the device. It affects a broad range of UniFi hardware -Dream Machines/Routers/Wall, Cloud Gateways, Cloud Keys, NVR/EVR, NAS, Enterprise Firewall Core, and more. CVE-2026-54400 is an improper access control flaw in the UniFi Access Application allowing privilege escalation on the host, exploitable by a network-adjacent actor who already holds high privileges. Both are remotely exploitable with no user interaction and result in full host compromise. 👉Update UniFi OS to 5.1.19 and UniFi Access Application to 4.2.29.

    Post summary

    The SA Bulletin 066 announces two critical vulnerabilities in Ubiquiti UniFi devices that enable remote command injection and privilege escalation, and recommends updating to specific firmware versions to remediate the issues.

    00010132
    236 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-54402: UniFi OS Command Injection Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04rKPCv0

    Post summary

    The snippet only names the CVE within a generic article title, without providing explicit details on exploitation, mitigation, or tooling.

    0000045
    32 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Ubiquiti ❗ CVE-2026-54402 ❗ CVE-2026-50747 ❗ CVE-2026-50746 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-ubiquiti-5/ https://t.co/X2hc3s6LUX

    Post summary

    The post announces three CVE identifiers for Ubiquiti products but provides no technical specifics, exploit details, or mitigation information.

    00000174
    6.7K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-54402 (CVSS 9.9) Improper input validation in UniFi OS allows authenticated attackers to execute commands remotely. Low privileges required, network accessible. Affected: UniFi OS devices Patch immediately! #CVE #Vulnerability #PatchNow https://t.co/6nEiQHVXqB

    Post summary

    The tweet announces a critical UniFi OS vulnerability (CVE‑2026‑54402) and urges users to apply the patch immediately.

    0000057
    71 followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    CVE-2026-54402 (CVSS 9.9) impacts UniFi OS. Organizations using UniFi should check for updates and review exposure. https://nvd.nist.gov/vuln/detail/CVE-2026-54402 http://adkcyber.com via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/S3u14b88h9

    Post summary

    The tweet announces CVE-2026-54402, a high‑severity vulnerability affecting UniFi OS, and urges organizations to update and review exposure.

    0000045
    92 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-54402 Command Injection via Improper Input Validation in UniFi OS https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-54402

    Post summary

    The text lists CVE‑2026‑54402 with a brief mention of a command injection flaw in UniFi OS, but provides no further detail on exploits, patches, or active exploitation.

    00000114
    4.1K followersView on X
CPE platform detail63 entries

63 of 63 entries

PartVendorProductVersionTarget SWTarget HW
HWuienterprise_firewall_core---
OSuienterprise_firewall_core_firmware---
HWuienterprise_fortress_gateway---
OSuienterprise_fortress_gateway_firmware---
HWuienterprise_network_video_recorder---
HWuienterprise_network_video_recorder_core---
OSuienterprise_network_video_recorder_core_firmware---
OSuienterprise_network_video_recorder_firmware---
HWuiunas_2---
OSuiunas_2_firmware---
HWuiunas_4---
OSuiunas_4_firmware---
HWuiunas_pro---
HWuiunas_pro_4---
OSuiunas_pro_4_firmware---
HWuiunas_pro_8---
OSuiunas_pro_8_firmware---
OSuiunas_pro_firmware---
HWuiunifi_cloud_gateway_fiber---
OSuiunifi_cloud_gateway_fiber_firmware---
HWuiunifi_cloud_gateway_industrial---
OSuiunifi_cloud_gateway_industrial_firmware---
HWuiunifi_cloud_gateway_max---
OSuiunifi_cloud_gateway_max_firmware---
HWuiunifi_cloud_gateway_ultra---
OSuiunifi_cloud_gateway_ultra_firmware---
HWuiunifi_cloud_key_plus---
OSuiunifi_cloud_key_plus_firmware---
HWuiunifi_cloudkey---
HWuiunifi_cloudkey_enterprise---
OSuiunifi_cloudkey_enterprise_firmware---
OSuiunifi_cloudkey_firmware---
HWuiunifi_dream_machine---
HWuiunifi_dream_machine_beast---
OSuiunifi_dream_machine_beast_firmware---
OSuiunifi_dream_machine_firmware---
HWuiunifi_dream_machine_pro---
OSuiunifi_dream_machine_pro_firmware---
HWuiunifi_dream_machine_pro_max---
OSuiunifi_dream_machine_pro_max_firmware---
HWuiunifi_dream_machine_special_edition---
OSuiunifi_dream_machine_special_edition_firmware---
HWuiunifi_dream_router---
HWuiunifi_dream_router_5g_max---
OSuiunifi_dream_router_5g_max_firmware---
HWuiunifi_dream_router_7---
OSuiunifi_dream_router_7_firmware---
OSuiunifi_dream_router_firmware---
HWuiunifi_dream_wall---
OSuiunifi_dream_wall_firmware---
HWuiunifi_express_7---
OSuiunifi_express_7_firmware---
HWuiunifi_network_video_recorder---
OSuiunifi_network_video_recorder_firmware---
HWuiunifi_network_video_recorder_g2---
OSuiunifi_network_video_recorder_g2_firmware---
HWuiunifi_network_video_recorder_g2_pro---
OSuiunifi_network_video_recorder_g2_pro_firmware---
HWuiunifi_network_video_recorder_instant---
OSuiunifi_network_video_recorder_instant_firmware---
HWuiunifi_network_video_recorder_pro---
OSuiunifi_network_video_recorder_pro_firmware---
Appuiunifi_os_server---

Explore more