THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, specifically targeting Ubiquiti UniFi OS and Lantronix EDS5000. The vulnerabilities include:
1. CVE-2025-67038: A code injection flaw in Lantronix EDS5000, which lacks proper username sanitization allowing arbitrary command execution.
2. CVE-2026-34908: An improper access control vulnerability in Ubiquiti UniFi OS with a critical CVSS score of 10.0, enabling unauthorized system modifications.
3. CVE-2026-34909: A path traversal vulnerability in UniFi OS, though details are limited.
4. CVE-2026-34910: Another critical flaw (CVSS 10.0) in UniFi OS leading to potential command injection. Federal agencies must remediate these vulnerabilities by June 26, 2026, to safeguard against potential exploits.