CVE-2026-34910
KEVCRITICAL 10.0EPSS 87.5%
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
- CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS
- 87.47% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2026-06-23
- Nuclei
- critical
- Published
- 2026-05-22
- Updated
- 2026-06-24
Proof-of-concept exploits (4)
- https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mi…
- Boreas37/CVE-2026-34910-PoC6★ · 2026-08-21
- gagaltotal/CVE-2026-34910-unifi-poc0★ · 2026-08-22
- BoredHackerBlog/unifi_5.0.6_exploitation