Ui: community verdicts
5 notable / known-exploited Ui CVEs the community has triaged.
- CVE-2026-34910CRIT 10KEVEPSS 79%
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
- CVE-2026-34908CRIT 10KEVEPSS 2%
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
- CVE-2026-34909CRIT 10KEVEPSS 2%
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.
- CVE-2026-33000CRIT 9.1Real · low riskEPSS 1%
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
- CVE-2026-34911HIGH 7.7Real · low riskEPSS 1%
A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information.