CRITICAL
CVE-2026-34910
CVSS
10
KEV
Description
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
Summary dbcve.org
This is an improper input validation vulnerability in UniFi OS devices that allows remote command injection. An attacker with network access can exploit unsanitized input fields to inject and execute arbitrary OS commands on the affected device, potentially compromising the entire network infrastructure managed by the device.
Mitigation
Apply vendor-supplied patches from Ubiquiti for UniFi OS devices immediately upon release. In the interim, restrict network access to management interfaces and implement network segmentation to limit exposure.
Weakness (CWE)
CWE-20
Improper Input Validation
EPSS Score
87.47%
Probability of exploitation in next 30 days
99.7th percentile
References
https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34910
US Government Resource
https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/
Exploit, Third Party Advisory
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.