CISA warns that threat actors are targeting three critical vulnerabilities in Ubiquiti devices, identified as CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, all rated with a CVSS score of 10/10. These flaws allow unauthorized access and command injection, and although patches were released last month, they were reportedly exploited in the wild to create rogue admin accounts. CISA has added these vulnerabilities to its Known Exploited Vulnerabilities catalog, urging federal agencies to act swiftly. A closely related vulnerability, CVE-2025-67038, also poses a severe threat, enabling command injection with root privileges.
CISA urges patching as hackers exploit critical Ubiquiti flaws
CyberSIXT Evidence Panel
Article by CyberSIXT