The Gear We Install Had a Bad Quarter

We deploy Ubiquiti UniFi networking equipment. So this isn't an article about somebody else's problem.

We deploy Ubiquiti UniFi networking equipment. So this isn't an article about somebody else's problem. Ubiquiti's most recent security bulletin, published August 26, lists 22 separate flaws across the UniFi range. Three of them scored 10 out of 10 — the highest severity rating that exists. Two earlier bulletins in May and July push the three-month total past fifty. If you have UniFi in your building, the part you need is four paragraphs down. The technical part — you can skip this box Bulletin 067, August 26, 2026: 22 vulnerabilities. Three at CVSS 10.0 — CVE-2026-77537 (unauthenticated command injection, UniFi Protect Application), CVE-2026-77550 (CRLF-sequence authentication bypass, UniFi OS) and CVE-2026-77554 (unauthenticated command injection, UniFi Talk). Affected: UniFi OS Server 5.1.21 and earlier; Cloud Keys, NVRs, Enterprise NVRs, Enterprise NAS, NAS, Dream Machines, Enterprise Firewall Core, Dream Routers, Enterprise Fortress Gateway, Cloud Gateways, Dream Wall and Express 7 on 5.1.26 and earlier; UniFi Express 4.0.16 and earlier; plus Protect 7.1.87, Network Application 10.4.57, Access 4.3.3, Talk 5.2.7, Connect 3.24.20, UID Enterprise Agent 1.61.8, Connect Display Cast Pro 1.0.108, Enterprise A/V Bridge 1.0.10 and Protect AI Key 2.1.3, each "and earlier." Every one of the 22 is credited to an outside researcher. Earlier: Bulletin 064 (May, reported as three at CVSS 10.0) and Bulletin 066 (July 7, reported as 25 flaws). What that actually means "Ten out of ten" is the top of the severity scale. For two of the three it means an attacker on your network needs no password and no help from anyone — they just send the request. "And earlier" is the direction that matters. Old versions are the affected ones — if your console is behind the numbers below, that's the problem. Every one of the 22 has a researcher's name on it. Outside people found these and told Ubiquiti, who fixed and published. Brandon Rossi is credited on six. And the part that matters most: these are fixed. Which makes this a question about whether your equipment took the updates, not whether the manufacturer did its job. What to do, and it takes about ten minutes Open your UniFi console and check two things: the version, and whether automatic updates are on. Operating system: UniFi OS Server 5.1.37 or later. Dream Machines, Cloud Gateways, Cloud Keys, Dream Routers, Dream Wall, video recorders and Express 7 — 5.1.31. Network storage — 5.1.32. UniFi Express — 4.0.17. Then the applications separately — they update on their own schedules, and that's where most of the 22 landed: Protect 7.2.105, Network 10.5.67, Access 4.3.5, Talk 5.3.2, Connect 3.24.22. A console reporting it's up to date is telling you about itself, not everything running on it. If we manage your network this is already done. If we don't, the version numbers above are enough for whoever does. Why we're telling you this about our own equipment Because the alternative is worse. We could have written about somebody else's firewall — there was one available this week. Easier post, and it would have implied a cleanliness we don't have. So, plainly: we chose UniFi, we install it, and we'd choose it again. Fifty findings in a quarter reads alarmingly until you look at who found them. Every one of August's 22 is credited to an outside researcher by name. That isn't a product falling apart — it's a disclosure programme working, and the alternative to a vendor publishing a lot isn't a safer vendor, it's one nobody is checking. A short bulletin can mean a clean quarter or an empty inbox, and from outside you can't tell which. What separates businesses isn't the vendor's flaw count. It's whether fixes ship quickly and whether somebody installs them. That second half is the one that gets skipped, and it's rarely anyone's fault. "Keep the network gear current" just doesn't tend to be written down as somebody's job.