Ubiquiti releases patches for three critical flaws in UniFi Protect, Talk, and OS

Ubiquiti has released patches for three maximum-severity vulnerabilities affecting its UniFi Protect, UniFi OS, and UniFi Talk applications. The flaws, including improper input validation, CRLF injection, and command injection, can be exploited remotely without authentication. The company recommends updating to the latest versions, though it has not confirmed any in-the-wild exploitation.
The three vulnerabilities span Ubiquiti's core product lines: the Protect video surveillance platform, the Talk VoIP system, and the underlying UniFi OS that powers network devices. Each flaw can be triggered remotely without authentication and requires no user interaction, making them especially dangerous for exposed systems. Censys currently tracks over 100,000 UniFi OS instances visible on the internet, though that figure may include historical scan data and honeypots.
Ubiquiti's security track record adds urgency to this disclosure. In February 2024, the FBI dismantled Moobot, a botnet built from Ubiquiti Edge OS routers used by Russian military intelligence for proxy traffic. More recently, in June, CISA ordered federal agencies to patch three other max-severity UniFi OS flaws within three days after confirming active exploitation, with Bishop Fox later showing those flaws could be chained into elevated remote code execution.
These patches affect a broad user base, from small businesses running video surveillance to enterprises managing distributed networks through UniFi OS. Because the flaws require no authentication and are low-complexity, unpatched devices could be swept into botnets or used as footholds for deeper network intrusion, as seen with previous Ubiquiti exploits. Organizations that delay updates may face operational disruption, data exposure, or regulatory scrutiny, particularly those in sectors with compliance obligations. Individual users of UniFi Protect cameras could also face privacy risks if surveillance footage is compromised.